CVE-2014-3702

CWE-22Path Traversal4 documents4 sources
Severity
9.1CRITICAL
EPSS
1.1%
top 21.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 16
Latest updateMay 17

Description

Directory traversal vulnerability in eNovance eDeploy allows remote attackers to create arbitrary directories and files and consequently cause a denial of service (resource consumption) via a .. (dot dot) the session parameter.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HExploitability: 3.9 | Impact: 5.2

Affected Packages1 packages

NVDredhat/edeploy8 versions+7

🔴Vulnerability Details

2
GHSA
GHSA-cqv6-gvj3-rfwc: Directory traversal vulnerability in eNovance eDeploy allows remote attackers to create arbitrary directories and files and consequently cause a denia2022-05-17
CVEList
CVE-2014-3702: Directory traversal vulnerability in eNovance eDeploy allows remote attackers to create arbitrary directories and files and consequently cause a denia2017-10-16

💬Community

1
Bugzilla
CVE-2014-3702 eDeploy: Path traversal in the session parameter2014-10-16
CVE-2014-3702 (CRITICAL CVSS 9.1) | Directory traversal vulnerability i | cvebase.io