Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cert6, it is possible to read any arbitrary file even when the `live_dangerously` is not enabled. This allows arbitrary files to be read. Asterisk versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cert6, contain a fix for this issue.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2023-12-14 20:15
Updated : 2023-12-29 00:15
NVD link : CVE-2023-49294
Mitre link : CVE-2023-49294
CVE.ORG link : CVE-2023-49294
JSON object : View
Products Affected
digium
- asterisk
sangoma
- certified_asterisk
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')