Directory traversal in the Compress feature in Pydio Cells 2.2.9 allows remote authenticated users to overwrite personal files, or Cells files belonging to any user, via the format parameter.
References
| Link | Resource |
|---|---|
| https://charonv.net/Pydio-Broken-Access-Control/ | Third Party Advisory |
| https://github.com/pydio/cells/releases/tag/v2.2.12 | Release Notes Third Party Advisory |
| https://pydio.com/fr/community/releases/pydio-cells/pydio-cells-enterprise-2212 | Product Vendor Advisory |
| https://charonv.net/Pydio-Broken-Access-Control/ | Third Party Advisory |
| https://github.com/pydio/cells/releases/tag/v2.2.12 | Release Notes Third Party Advisory |
| https://pydio.com/fr/community/releases/pydio-cells/pydio-cells-enterprise-2212 | Product Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2021-09-30 19:15
Updated : 2024-11-21 06:26
NVD link : CVE-2021-41323
Mitre link : CVE-2021-41323
CVE.ORG link : CVE-2021-41323
JSON object : View
Products Affected
pydio
- cells
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
