HIGH
nothub mrpack-install <= v0.16.2 is vulnerable to Directory Traversal
Published Jun 26, 2023
8.8
HIGHCVSS 3.1
EPSS 0.60%
Description
nothub mrpack-install <= v0.16.2 is vulnerable to Directory Traversal.
Affected products
No data.
- < 0.16.3
No data.
No Red Hat product state for this CVE.
github.com/nothub/mrpack-install
Go
Introduced 0 Fixed 0.16.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/nothub/mrpack-install | 0 | 0.16.3 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://github.com/advisories/GHSA-r887-gfxh-m9rr Advisory
- https://github.com/nothub/mrpack-install/commit/a1f424b6a616d2de95228781eef3b92b9769f23c
- https://github.com/nothub/mrpack-install/releases/tag/v0.16.3
- https://github.com/nothub/mrpack-install/security/advisories/GHSA-r887-gfxh-m9rr Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-25307
- https://quiltmc.org/en/blog/2023-02-04-five-installer-vulnerabilities/ Exploit
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jun 26, 2023
Updated Dec 4, 2024
Reserved Feb 6, 2023
Link CVE-2023-25307
CISA Vulnrichment
GHSA-R887-GFXH-M9RR Updated Dec 4, 2024