logo

Database

Lack of data validation - Path Traversal In st

Description

Directory Traversal in st Versions of st prior to 0.2.5 are affected by a directory traversal vulnerability. Vulnerable versions fail to properly handle URL encoded dots, which caused %2e to be interpreted as . by the filesystem, resulting the potential for an attacker to read sensitive files on the server.

Recommendation

Update to version 0.2.5 or later.

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions
FLAT-LMHJO – Vulnerability | Fluid Attacks Database