Impact
A flaw in the StaticFileRouter component of Drogon allows an attacker to craft a URL that resolves to arbitrary files on the host filesystem. The vulnerability is triggered by manipulating path components in the route, giving the attacker read access to files outside the intended static directory. This path traversal can be performed from a remote host, with the exploit already published on public channels.
Affected Systems
The affected product is Drogon, a C++ web framework, on Windows builds up to versions 1.9.13-1 and 10.0-beta.3. The issue resides in the StaticFileRouter::route implementation in StaticFileRouter.cc. Users deploying these drogon releases with the static file router exposed to the internet are at risk.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate to high severity, primarily compromising confidentiality through information disclosure. The EPSS information is not available, but a published exploit exists, suggesting realistic exploitation potential. The vulnerability is not listed in the CISA KEV catalog, though the remote attack vector and availability of the exploit warrant immediate attention.
OpenCVE Enrichment