Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Rapid7 Velociraptor Directory Traversal Vulnerability
Vulnerability Description
Rapid7 Velociraptor versions before 0.75.6 contain a directory traversal issue on Linux servers that allows a rogue client to upload a file which is written outside the datastore directory. Velociraptor is normally only allowed to write in the datastore directory. The issue occurs due to insufficient sanitization of directory names which end with a ".", only encoding the final "." AS "%2E". Although files can be written to incorrect locations, the containing directory must end with "%2E". This limits the impact of this vulnerability, and prevents it from overwriting critical files.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
Rapid7 Velociraptor 安全漏洞
Vulnerability Description
Rapid7 Velociraptor是美国Rapid7公司的一个数字取证与事件响应平台。 Rapid7 Velociraptor 0.75.6之前版本存在安全漏洞,该漏洞源于Linux服务器上目录名清理不足,可能导致目录遍历和文件写入错误位置。
CVSS Information
N/A
Vulnerability Type
N/A