CVE-2018-11789
Severity
7.5HIGH
EPSS
1.7%
top 17.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 21
Latest updateMay 14
Description
When accessing the heron-ui webpage, people can modify the file paths outside of the current container to access any file on the host. Example woule be modifying the parameter path= to go to the directory you would like to view. i.e. ..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd.
CVSS vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6
Affected Packages2 packages
🔴Vulnerability Details
2GHSA▶
GHSA-h68w-6v33-769g: When accessing the heron-ui webpage, people can modify the file paths outside of the current container to access any file on the host↗2022-05-14
CVEList▶
CVE-2018-11789: When accessing the heron-ui webpage, people can modify the file paths outside of the current container to access any file on the host↗2019-03-18