Path traversal in hiawatha - CVE-2019-8358

 

Path traversal in hiawatha - CVE-2019-8358

Published: February 14, 2019 / Updated: February 18, 2019


Vulnerability identifier: #VU17695
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-8358
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to conduct directory traversal attack.

The weakness exists due to path traversal when AllowDotFiles is enabled. A remote attacker can conduct directory traversal attack and cause the service ot crash or execute arbitrary code with elevated privileges.

Successful exploitation of the vulnerability may result in system compromise.

Affected software

hiawatha
Arch Linux
SUSE Linux
Opensuse

How to mitigate CVE-2019-8358

Update to version 10.8.4.

hiawatha - update to 10.8.4

External References

Related Security Bulletins