2.5
CVE-2026-104994
- EPSS 0.2%
- Veröffentlicht 02.10.2026 19:52:36
- Zuletzt bearbeitet 05.10.2026 18:17:33
- Erkennungen
Trivy before 0.71.0 allows directory traversal in Terraform filesystem functions when they try to access pathnames above the scan root. The risk occurs when using misconf scanning on untrusted input (e.g., upon a third-party pull request that contains a Terraform configuration), if sensitive data can be found at those unintended pathnames, and an adversary can then view a sensitive data value within scan output.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstelleraquasec
≫
Produkt
Trivy
Default Statusunaffected
Version
0
Version <
0.71.0
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.085 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| MITRE | 2.5 | 1 | 1.4 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
|
CWE-24 Path Traversal: '../filedir'
The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize "../" sequences that can resolve to a location that is outside of that directory.
https://github.com/aquasecurity/trivy/security/advisories/GHSA-87hp-4m93-274g
https://github.com/aquasecurity/trivy/commit/9d91b888cf63023e9c09b64259a4c1cea8dfe993
https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md
https://github.com/aquasecurity/trivy/pull/10664