← Voltar para CVEs
CVE-2014-5269
N/ADescricao
Plack::App::File in Plack before 1.0031 removes trailing slash characters from paths, which allows remote attackers to bypass the whitelist of generated files and obtain sensitive information via a crafted path, related to Plack::Middleware::Static.
Detalhes CVE
Pontuacao CVSS v3.1N/A
Publicado9/4/2014
Ultima modificacao4/12/2025
Fontenvd
Avistamentos honeypot0
Produtos afetados
plack_project:plack
Fraquezas (CWE)
CWE-264
Referencias
http://api.metacpan.org/source/MIYAGAWA/Plack-1.0031/Changes(security@debian.org)
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/137099.html(security@debian.org)
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/137115.html(security@debian.org)
http://seclists.org/oss-sec/2014/q3/384(security@debian.org)
http://www.osvdb.org/109928(security@debian.org)
https://github.com/avar/Plack/commit/bc1731dbb53850c380875ad683cd87c8ec99eee3(security@debian.org)
https://github.com/plack/Plack/issues/405(security@debian.org)
http://api.metacpan.org/source/MIYAGAWA/Plack-1.0031/Changes(af854a3a-2127-422b-91ae-364da2661108)
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/137099.html(af854a3a-2127-422b-91ae-364da2661108)
http://lists.fedoraproject.org/pipermail/package-announce/2014-August/137115.html(af854a3a-2127-422b-91ae-364da2661108)
http://seclists.org/oss-sec/2014/q3/384(af854a3a-2127-422b-91ae-364da2661108)
http://www.osvdb.org/109928(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/avar/Plack/commit/bc1731dbb53850c380875ad683cd87c8ec99eee3(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/plack/Plack/issues/405(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.