PartKeepr versions up to v1.4.0, loads attachments using a URL while creating a part and allows the use of the 'file://' URI scheme, allowing an authenticated user to read local files.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: Fluid Attacks
Published: 2022-01-07T21:59:38
Updated: 2024-08-03T03:21:48.988Z
Reserved: 2022-01-05T00:00:00
Link: CVE-2022-22701
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-01-10T14:12:48.547
Modified: 2024-11-21T06:47:16.840
Link: CVE-2022-22701
Redhat
No data.