CVE-2022-43753

CWE-22Path Traversal3 documents3 sources
Severity
4.3MEDIUM
EPSS
0.3%
top 48.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 10

Description

A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spacewalk/Uyuni of SUSE Linux Enterprise Module for SUSE Manager Server 4.2, SUSE Linux Enterprise Module for SUSE Manager Server 4.3, SUSE Manager Server 4.2 allows remote attackers to read files available to the user running the process, typically tomcat. This issue affects: SUSE Linux Enterprise Module for SUSE Manager Server 4.2 hub-xmlrpc-api-0.7-150300.3.9.2, inter-server-sync-0.2.4-150300.8.2

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages5 packages

CVEListV5suse/suse_linux_enterprise_module_for_suse_manager_server_4.2hub-xmlrpc-api-0.7-150300.3.9.2, inter-server-sync-0.2.4-150300.8.25.2, locale-formula-0.3-150300.3.3.2, py27-compat-salt-3000.3-150300.7.7.26.2, python-urlgrabber-3.10.2.1py2_3-150300.3.3.2, spacecmd-4.2.20-150300.4.30.2, spacewalk-backend-4.2.25-150300.4.32.4, spacewalk-client-tools-4.2.21-150300.4.27.3, spacewalk-java-4.2.43-150300.3.48.2, spacewalk-utils-4.2.18-150300.3.21.2, spacewalk-web-4.2.30-150300.3.30.3, susemanager-4.2.38-150300.3.44.3, susemanager-doc-indexes-4.2-150300.12.36.3, susemanager-docs_en-4.2-150300.12.36.2, susemanager-schema-4.2.25-150300.3.30.3, susemanager-sls4.2.28
CVEListV5suse/suse_manager_server_4.2release-notes-susemanager4.2.10
NVDsuse/manager_server4.24.2.10+1
NVDuyuni-project/uyuni< 2022.10

🔴Vulnerability Details

2
GHSA
GHSA-c2p9-h64p-qvv4: A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in spacewalk/Uyuni of SUSE Linux Enterprise Module for2022-11-10
CVEList
SUMA/UYUNI arbitrary file disclosure vulnerability in ScapResultDownload2022-11-10
CVE-2022-43753 (MEDIUM CVSS 4.3) | A Improper Limitation of a Pathname | cvebase.io