Impact
The vulnerability described is a path traversal flaw that allows an attacker to read arbitrary files or directories outside of the intended restricted directory. This flaw can expose confidential information stored on the system. No other impact such as modification or execution is mentioned in the description.
Affected Systems
Affected products include Adobe Content Credentials Command-Line Tool, Adobe Content Credentials JavaScript SDK, and Adobe Content Credentials Rust SDK. Version details are not specified, implying that all current releases may be impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity issue. The EPSS score of less than 1% suggests a very low, but non-zero, likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could supply a maliciously crafted path to the affected component, exploit the path traversal without user interaction, and read files outside the intended directory. The scope change means the attacker’s read capability may extend beyond the originally restricted area.
OpenCVE Enrichment