ZeroHour

CVE-2023-35844

PoC
CVSS 3.1
7.5 high
EPSS
6%p93
Published
()
Modified
Description

packages/backend/src/routers in Lightdash before 0.510.3 has insecure file endpoints, e.g., they allow .. directory traversal and do not ensure that an intended file extension (.csv or .png) is used.

Vendors
lightdash
Products
lightdash
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.