Cesanta Mongoose security bypass | CVE-2022-25299
NAME
Cesanta Mongoose security bypass
- Platforms Affected:
Cesanta Mongoose 7.5 - Risk Level:
9.8 - Exploitability:
Unproven - Consequences:
Bypass Security
DESCRIPTION
Cesanta Mongoose could allow a remote attacker to bypass security restrictions, caused by an unsafe handling of file names during upload using mg_http_upload() method. By sending a specially-crafted request, an attacker could exploit this vulnerability to write files to arbitrary locations outside the designated target folder.
CVSS 3.0 Information
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Access Vector: Network
- Access Complexity: Low
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
- Remediation Level: Official Fix
MITIGATION
Upgrade to the latest version of Mongoose (7.6 or later), available from the Mongoose GIT Repository. See References.
- Reference Link:
https://security.snyk.io/vuln/SNYK-UNMANAGED-CESANTAMONGOOSE-2404180 - Reference Link:
https://github.com/cesanta/mongoose/commit/c65c8fdaaa257e0487ab0aaae9e8f6b439335945
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.