An issue was discovered in server.js in etcd-browser 87ae63d75260. By supplying a /../../../ Directory Traversal input to the URL's GET request while connecting to the remote server port specified during setup, an attacker can retrieve local operating system files from the remote system.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2023-12-07T00:00:00

Updated: 2024-08-02T20:45:40.766Z

Reserved: 2023-10-22T00:00:00

Link: CVE-2023-46307

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2023-12-07T06:15:54.683

Modified: 2023-12-12T17:06:02.260

Link: CVE-2023-46307

cve-icon Redhat

No data.