A Directory Traversal vulnerability in ladle dev server 2.5.1 and earlier allows an attacker on the same network to read files accessible to the user via GET requests.
History

Thu, 21 Nov 2024 15:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-22
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2024-03-28T00:00:00

Updated: 2024-11-21T15:09:22.578Z

Reserved: 2023-02-06T00:00:00

Link: CVE-2023-25341

cve-icon Vulnrichment

Updated: 2024-08-02T11:18:36.261Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-28T22:15:09.170

Modified: 2024-11-21T15:15:09.430

Link: CVE-2023-25341

cve-icon Redhat

No data.