CVE-2022-38731
Last modified
CVE-2022-38731 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Qaelum DOSE 18.08 through 21.1 before 21.2 allows Directory Traversal via the loadimages name parameter. It allows a user to specify an arbitrary location on the server's filesystem from which to load an image. EPSS estimates a 0.73% chance of exploitation in the next 30 days.
Description
Qaelum DOSE 18.08 through 21.1 before 21.2 allows Directory Traversal via the loadimages name parameter. It allows a user to specify an arbitrary location on the server's filesystem from which to load an image. (Only images are displayed to the attacker. All other files are loaded but not displayed.) The Content-Type response header reflects the actual content type of the file being requested. This allows an attacker to enumerate files on the local system. Additionally, remote resources can be requested via a UNC path, allowing an attacker to coerce authentication out from the server to the attackers machine.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qaelum | Dose | >= 18.08, < 21.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-38731?
How severe is CVE-2022-38731?
How do I fix CVE-2022-38731?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-3872An off-by-one read/write issue was found in the SDHCI device…8.6
- CVE-2022-38723Gravitee API Management before 3.15.13 allows path traversal…8.6
- CVE-2022-38724Silverstripe silverstripe/framework through 4.11.0, silverst…5.4
- CVE-2022-38725An integer overflow in the RFC3164 parser in One Identity sy…7.5
- CVE-2022-3873Cross-site Scripting (XSS) - DOM in GitHub repository jgraph…6.1
- CVE-2022-38730Docker Desktop for Windows before 4.6 allows attackers to ov…6.3
- CVE-2022-38732SnapCenter versions prior to 4.7 shipped without Content Sec…7.5
- CVE-2022-38733OnCommand Insight versions 7.3.1 through 7.3.14 are suscepti…8.6
- CVE-2022-38734StorageGRID (formerly StorageGRID Webscale) versions prior t…7.5
- CVE-2022-38735Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-38736Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2022-38737Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2022-38731?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
