CVE-2022-31546Path Traversal in Project Glance

CWE-22Path Traversal3 documents3 sources
Severity
9.3CRITICALNVD
EPSS
0.4%
top 37.27%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 11
Latest updateJul 12

Description

The nlpweb/glance repository through 2014-06-27 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:LExploitability: 3.9 | Impact: 4.7

Affected Packages1 packages

NVDglance_project/glance2014-06-27

🔴Vulnerability Details

2
GHSA
GHSA-29vr-p37f-25gc: The nlpweb/glance repository through 2014-06-27 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely2022-07-12
CVEList
CVE-2022-31546: The nlpweb/glance repository through 2014-06-27 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely2022-07-11
CVE-2022-31546 — Path Traversal in Project Glance | cvebase