Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-26315: Directory Traversal Vulnerability · Issue #223 · claudiodangelis/qrcp

qrcp through 0.8.4, in receive mode, allows …/ Directory Traversal via the file name specified by the uploader.

CVE
#vulnerability#windows#ubuntu#git

While qrcp works on receive mode, uploader can edit the file name in HTTP request and add "…/". Meanwhile, qrcp doesn’t check legality of file name which lead to directory traversal.
Env: qrcp-0.8.4, Windows 10 x86_64, Ubuntu 20.04 x86_64
Poc:
image
image
image

credit: starryloki,lu0sf

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907