CVE-2018-11789

CWE-22Path Traversal3 documents3 sources
Severity
7.5HIGH
EPSS
1.7%
top 17.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 21
Latest updateMay 14

Description

When accessing the heron-ui webpage, people can modify the file paths outside of the current container to access any file on the host. Example woule be modifying the parameter path= to go to the directory you would like to view. i.e. ..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDapache/heron0.13.00.17.8
CVEListV5apache_incubator_heronApache Incubator Heron 0.13.0 to 0.17.8

🔴Vulnerability Details

2
GHSA
GHSA-h68w-6v33-769g: When accessing the heron-ui webpage, people can modify the file paths outside of the current container to access any file on the host2022-05-14
CVEList
CVE-2018-11789: When accessing the heron-ui webpage, people can modify the file paths outside of the current container to access any file on the host2019-03-18
CVE-2018-11789 (HIGH CVSS 7.5) | When accessing the heron-ui webpage | cvebase.io