Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-rmcx-fg5w-x8j9: FusionAuth vulnerable to directory traversal attack

FusionAuth before 1.41.3 allows a file outside of the application root to be viewed or retrieved using an HTTP request. To be specific, an attacker may be able to view or retrieve any file readable by the user running the FusionAuth process.

ghsa
#git#auth

FusionAuth vulnerable to directory traversal attack

High severity GitHub Reviewed Published Nov 28, 2022 • Updated Nov 30, 2022

Related news

CVE-2022-45921: Mitigate traversal attack - CVE-2022-45921 · Issue #1983 · FusionAuth/fusionauth-issues

FusionAuth before 1.41.3 allows a file outside of the application root to be viewed or retrieved using an HTTP request. To be specific, an attacker may be able to view or retrieve any file readable by the user running the FusionAuth process.