nothub mrpack-install <= v0.16.2 is vulnerable to Directory Traversal.
References
| Link | Resource |
|---|---|
| https://github.com/nothub/mrpack-install/security/advisories/GHSA-r887-gfxh-m9rr | Vendor Advisory |
| https://quiltmc.org/en/blog/2023-02-04-five-installer-vulnerabilities/ | Exploit |
Configurations
History
No history.
Information
Published : 2023-06-26 15:15
Updated : 2023-07-03 19:19
NVD link : CVE-2023-25307
Mitre link : CVE-2023-25307
CVE.ORG link : CVE-2023-25307
JSON object : View
Products Affected
mrpack-install_project
- mrpack-install
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
