CVE-2022-2653
With this vulnerability an attacker can read many sensitive files like configuration files, or the /proc/self/environ file, that contains the environment variable used by the web server that includes database credentials.
Does this matter?
Lower severity and a low EPSS score (0.96%). Track it; it rarely justifies an emergency change on its own.
Description
With this vulnerability an attacker can read many sensitive files like configuration files, or the /proc/self/environ file, that contains the environment variable used by the web server that includes database credentials. If the web server user is root, an attacker will be able to read any file in the system.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.96% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- planka/planka
- Source
- security@huntr.dev
References
- https://github.com/plankanban/planka/commit/ac1df5201dfdaf68d37f7e1b272bc137870d7418Patch, Third Party Advisory
- https://huntr.dev/bounties/5dff7cf9-8bb2-4f67-a02d-b94db5009d70Exploit, Issue Tracking, Patch, Third Party Advisory
- https://github.com/plankanban/planka/commit/ac1df5201dfdaf68d37f7e1b272bc137870d7418Patch, Third Party Advisory
- https://huntr.dev/bounties/5dff7cf9-8bb2-4f67-a02d-b94db5009d70Exploit, Issue Tracking, Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.