Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

PRP: request CVE-2021-3019 Lanproxy Directory Traversal #155

Closed
Aronld57 opened this issue Oct 9, 2021 · 0 comments
Closed

PRP: request CVE-2021-3019 Lanproxy Directory Traversal #155

Aronld57 opened this issue Oct 9, 2021 · 0 comments
Labels
Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this. PRP:Request

Comments

@Aronld57
Copy link

Aronld57 commented Oct 9, 2021

Hello,

I would like to start the implementation for a plugin that detects CVE-2021-3019 Lanproxy Directory Traversal.

Vulnerability details:ffay lanproxy 0.1 allows Directory Traversal to read /../conf/config.properties to obtain credentials for a connection to the intranet.

Type: Lanproxy Directory Traversal
Score: 7.50 high
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Reference:
- https://github.com/ffay/lanproxy/commits/master
- maybe-why-not/lanproxy#1

The vulnerability should have a relatively large impact radius. Yes,

Please let me know if this is in scope as I've already made the development .

@tooryx tooryx added the Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this. label Feb 1, 2024
@tooryx tooryx closed this as completed Feb 1, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Contributor queue When a contributor has already one issue/PR in review, we put the following ones on hold with this. PRP:Request
Projects
None yet
Development

No branches or pull requests

3 participants