CVE-2022-22701

Published

Severity

CVSS v3:
6.5 MEDIUM
CVSS v2:
4 MEDIUM

Description

PartKeepr versions up to v1.4.0, loads attachments using a URL while creating a part and allows the use of the 'file://' URI scheme, allowing an authenticated user to read local files.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:partkeepr:partkeepr:*:*:*:*:*:*:*:*n/a1.4.0 (including)*

External Links