rubedo_project Vulnerabilities and Affected Products
Vulnerabilities associated with rubedo.
Products
Clear product- rubedo1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-16836CRITICAL | rubedo_project rubedo Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attackers to read and execute arbitrary files outside of the service root path, as demonstrated by a /theme/default/img/%2e%2e/..//etc/passwd URI. | CVSS9.8v3.1 | EPSS61.4% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |