CVE-2018-16836

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
11/09/2018
Last modified:
05/02/2020

Description

Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attackers to read and execute arbitrary files outside of the service root path, as demonstrated by a /theme/default/img/%2e%2e/..//etc/passwd URI.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rubedo_project:rubedo:*:*:*:*:*:*:*:* 3.4.0 (including)