CVE-2017-16248
The Catalyst-Plugin-Static-Simple module before 0.34 for Perl allows remote attackers to read arbitrary files if there is a '.' character anywhere in the pathname, which differs from the intended policy of allowing access only when the filename itself…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.43%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Catalyst-Plugin-Static-Simple module before 0.34 for Perl allows remote attackers to read arbitrary files if there is a '.' character anywhere in the pathname, which differs from the intended policy of allowing access only when the filename itself has a '.' character.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 2.43% probability · 83th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- catalyst-plugin-static-simple project/catalyst-plugin-static-simple
- Source
- cve@mitre.org
References
- https://bugs.debian.org/880458Third Party Advisory
- https://metacpan.org/changes/distribution/Catalyst-Plugin-Static-SimpleRelease Notes
- https://rt.cpan.org/Public/Bug/Display.html?id=120558Issue Tracking, Third Party Advisory
- https://bugs.debian.org/880458Third Party Advisory
- https://metacpan.org/changes/distribution/Catalyst-Plugin-Static-SimpleRelease Notes
- https://rt.cpan.org/Public/Bug/Display.html?id=120558Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.