5.5

CVE-2024-10933

In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any '/' in readdir name validation to avoid unexpected directory traversal on untrusted file systems.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpenbsdOpenbsd Version < 7.4
OpenbsdOpenbsd Version7.4 Update-
OpenbsdOpenbsd Version7.4 Updateerrata_001
OpenbsdOpenbsd Version7.4 Updateerrata_002
OpenbsdOpenbsd Version7.4 Updateerrata_003
OpenbsdOpenbsd Version7.4 Updateerrata_004
OpenbsdOpenbsd Version7.4 Updateerrata_005
OpenbsdOpenbsd Version7.4 Updateerrata_006
OpenbsdOpenbsd Version7.4 Updateerrata_007
OpenbsdOpenbsd Version7.4 Updateerrata_008
OpenbsdOpenbsd Version7.4 Updateerrata_009
OpenbsdOpenbsd Version7.4 Updateerrata_010
OpenbsdOpenbsd Version7.4 Updateerrata_011
OpenbsdOpenbsd Version7.4 Updateerrata_012
OpenbsdOpenbsd Version7.4 Updateerrata_013
OpenbsdOpenbsd Version7.4 Updateerrata_014
OpenbsdOpenbsd Version7.4 Updateerrata_015
OpenbsdOpenbsd Version7.4 Updateerrata_016
OpenbsdOpenbsd Version7.4 Updateerrata_017
OpenbsdOpenbsd Version7.4 Updateerrata_018
OpenbsdOpenbsd Version7.4 Updateerrata_019
OpenbsdOpenbsd Version7.4 Updateerrata_020
OpenbsdOpenbsd Version7.4 Updateerrata_021
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.06% 0.187
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
9119a7d8-5eab-497f-8521-727c672e3725 4.1 0 0
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
9119a7d8-5eab-497f-8521-727c672e3725 5 1.3 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.