2024-12-08 03:06:42 +00:00

121 lines
3.6 KiB
JSON

{
"id": "CVE-2017-14196",
"sourceIdentifier": "cve@mitre.org",
"published": "2017-11-30T02:29:03.167",
"lastModified": "2024-11-21T03:12:20.467",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in Squiz Matrix from 5.3 through to 5.3.6.1 and 5.4.1.3. An information disclosure caused by a Path Traversal issue in the 'File Bridge' plugin allowed the existence of files outside of the bridged path to be confirmed."
},
{
"lang": "es",
"value": "Se ha descubierto un problema en Squiz Matrix desde la versi\u00f3n 5.3 hasta la 5.3.6.1 y en la versi\u00f3n 5.4.1.3. Una divulgaci\u00f3n de informaci\u00f3n provocada por un problema de salto de directorio en el plugin \"File Bridge\" permiti\u00f3 que existiesen archivos fuera de la ruta puente que se va a confirmar."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"attackVector": "NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "NONE",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"baseScore": 5.0,
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "NONE",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:squiz:matrix:*:*:*:*:*:*:*:*",
"versionStartIncluding": "5.3.0.0",
"versionEndIncluding": "5.3.6.1",
"matchCriteriaId": "D9159EBE-EC8A-448C-98B7-56D85B6554F5"
},
{
"vulnerable": true,
"criteria": "cpe:2.3:a:squiz:matrix:5.4.1.3:*:*:*:*:*:*:*",
"matchCriteriaId": "83BC8818-209D-4412-86FA-A3371B5132E9"
}
]
}
]
}
],
"references": [
{
"url": "http://devalias.net/devalias/2017/09/07/squiz-matrix-multiple-vulnerabilities/",
"source": "cve@mitre.org",
"tags": [
"Issue Tracking",
"Third Party Advisory"
]
},
{
"url": "http://devalias.net/devalias/2017/09/07/squiz-matrix-multiple-vulnerabilities/",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Issue Tracking",
"Third Party Advisory"
]
}
]
}