endpointlabs / VulnerableDotNetCore3Project

.Net Core 3.0
0 stars 0 forks source link

CVE-2022-1664 | dpkg (CWE-22) #16

Open mgulter opened 2 years ago

mgulter commented 2 years ago

A critical severity vulnerability has been discovered in your project.

Project Name: IssueTest

Scanner Name: trivy

Cwe ID: 22

Cwe Name: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)

Cwe Link: https://cwe.mitre.org/data/definitions/22.html

CVE ID: CVE-2022-1664

Target: nginx:latest (debian 11.3)

Packages:

References:

Training(Secure Code Warrior):

Tool Description: Dpkg::Source::Archive in dpkg, the Debian package management system, before version 1.21.8, 1.20.10, 1.19.8, 1.18.26 is prone to a directory traversal vulnerability. When extracting untrusted source packages in v2 and v3 source package formats that include a debian.tar, the in-place extraction can lead to directory traversal situations on specially crafted orig.tar and debian.tar tarballs.

Custom Description: NEW ENDPOINT TEST