GHSA-69rr-wvh9-6c4q
HIGHCVE-2014-3744Versions of st prior to 0.2.5 are affected by a directory traversal vulnerability. Vulnerable versions fail to properly handle URL encoded dots, which caused %2e to be interpreted as . by the filesystem, resulting the potential for an attacker to read sensitive files on the server.
- Affected
- < 0.2.5
- Fixed in
- 0.2.5
- Weakness
- CWE-22
- Published
- 2020-08-31
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereference