Gladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be incomplete, allowing authenticated attackers to extract sensitive files in the host machine.
References
Link | Resource |
---|---|
https://blog.moku.fr/cve/ | Third Party Advisory |
https://blog.moku.fr/cves/CVE-2023-47440/ | Third Party Advisory |
https://github.com/GladysAssistant/Gladys/pull/1918/commits/4f56ba250ff9f46578f1afa6a97e62e74bad83b7 | Patch |
Configurations
History
No history.
Information
Published : 2023-12-07 18:15
Updated : 2023-12-12 18:06
NVD link : CVE-2023-47440
Mitre link : CVE-2023-47440
CVE.ORG link : CVE-2023-47440
JSON object : View
Products Affected
gladysassistant
- gladys_assistant
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')