CVE-2023-35843

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
19/06/2023
Last modified:
12/12/2024

Description

NocoDB through 0.106.0 (or 0.109.1) has a path traversal vulnerability that allows an unauthenticated attacker to access arbitrary files on the server by manipulating the path parameter of the /download route. This vulnerability could allow an attacker to access sensitive files and data on the server, including configuration files, source code, and other sensitive information.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nocodb:nocodb:*:*:*:*:*:*:*:* 0.106.1 (including)