← Volver a CVEs
CVE-2014-5269
N/ADescripcion
Plack::App::File in Plack before 1.0031 removes trailing slash characters from paths, which allows remote attackers to bypass the whitelist of generated files and obtain sensitive information via a crafted path, related to Plack::Middleware::Static.
Detalles CVE
Puntuacion CVSS v3.1N/A
Publicado9/4/2014
Ultima modificacion4/12/2025
Fuentenvd
Avistamientos honeypot0
Productos afectados
plack_project:plack
Debilidades (CWE)
CWE-264
Referencias
http://api.metacpan.org/source/MIYAGAWA/Plack-1.0031/Changes(security@debian.org)
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/137099.html(security@debian.org)
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/137115.html(security@debian.org)
http://seclists.org/oss-sec/2014/q3/384(security@debian.org)
http://www.osvdb.org/109928(security@debian.org)
https://github.com/avar/Plack/commit/bc1731dbb53850c380875ad683cd87c8ec99eee3(security@debian.org)
https://github.com/plack/Plack/issues/405(security@debian.org)
http://api.metacpan.org/source/MIYAGAWA/Plack-1.0031/Changes(af854a3a-2127-422b-91ae-364da2661108)
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/137099.html(af854a3a-2127-422b-91ae-364da2661108)
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/137115.html(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/oss-sec/2014/q3/384(af854a3a-2127-422b-91ae-364da2661108)
http://www.osvdb.org/109928(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/avar/Plack/commit/bc1731dbb53850c380875ad683cd87c8ec99eee3(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/plack/Plack/issues/405(af854a3a-2127-422b-91ae-364da2661108)
Correlaciones IOC
Sin correlaciones registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.