CVE-2017-17042

HIGH7.5EPSS 0.41%

Arbitrary file read vulnerability in yard server

發布日:2017/12/21修改日:2026/4/28
也稱為:GHSA-gj4p-3wh3-2rmfDEBIAN-CVE-2017-17042

描述

lib/yard/core_ext/file.rb in the server in YARD before 0.9.11 does not block relative paths with an initial ../ sequence, which allows attackers to conduct directory traversal attacks and read arbitrary files.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

參考連結(6)