Jekyll through 3.6.2, 3.7.x through 3.7.3, and 3.8.x through 3.8.3 allows attackers to access arbitrary files by specifying a symlink in the "include" key in the "_config.yml" file.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2018-09-28 00:29
Updated : 2024-11-21 03:54
NVD link : CVE-2018-17567
Mitre link : CVE-2018-17567
CVE.ORG link : CVE-2018-17567
JSON object : View
Products Affected
jekyllrb
- jekyll
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')