CVE-2022-1554

Path Traversal due to `send_file` call in GitHub repository clinical-genomics/scout prior to 4.52.
Configurations

Configuration 1 (hide)

cpe:2.3:a:clinical-genomics:scout:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:40

Type Values Removed Values Added
References () https://github.com/clinical-genomics/scout/commit/952a2e2319af2d95d22b017a561730feac086ff1 - Patch, Third Party Advisory () https://github.com/clinical-genomics/scout/commit/952a2e2319af2d95d22b017a561730feac086ff1 - Patch, Third Party Advisory
References () https://huntr.dev/bounties/7acac778-5ba4-4f02-99e2-e4e17a81e600 - Exploit, Patch, Third Party Advisory () https://huntr.dev/bounties/7acac778-5ba4-4f02-99e2-e4e17a81e600 - Exploit, Patch, Third Party Advisory

Information

Published : 2022-05-03 09:15

Updated : 2024-11-21 06:40


NVD link : CVE-2022-1554

Mitre link : CVE-2022-1554

CVE.ORG link : CVE-2022-1554


JSON object : View

Products Affected

clinical-genomics

  • scout
CWE
CWE-36

Absolute Path Traversal

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')