etcd-browser 87ae63d75260 Directory Traversal
2023-11-28 23:54:48 Author: packetstormsecurity.com(查看原文) 阅读量:5 收藏

An issue was discovered in server.js in etcd-browser 87ae63d75260. By
supplying a /../../../ Directory Traversal input to the URL's GET
request while connecting to the remote server port specified during
setup, an attacker can retrieve local operating system files from the
remote system.

------------------------------------------

[Vulnerability Type]
Directory Traversal

------------------------------------------

[Vendor of Product]
https://hub.docker.com/r/buddho/etcd-browser

------------------------------------------

[Affected Product Code Base]
etcd-browser - Unknown

------------------------------------------

[Affected Component]
the server.js file does not validate the path for files.

------------------------------------------

[Attack Type]
Remote

------------------------------------------

[Impact Information Disclosure]
true

------------------------------------------

[CVE Impact Other]
Allow for a remote arbitrary user to obtain local operating system files

------------------------------------------

[Attack Vectors]
The attacker must supply a /../../ technique to the server application
running on the remote port specified during setup

------------------------------------------

[Reference]
https://hub.docker.com/r/buddho/etcd-browser
https://hub.docker.com/r/buddho/etcd-browser/tags

------------------------------------------

[Discoverer]
Kevin Randall


文章来源: https://packetstormsecurity.com/files/175954/etcdbrowser87ae63d75260-traversal.txt
如有侵权请联系:admin#unsafe.sh