blog.rstudio.com
https://blog.rstudio.com/2021/01/13/shiny-server-1-5-16-update CVE-2021-3374
MEDIUMNuclei
Rstudio Shiny Server <1.5.16 - Local File Inclusion
Record summary
CVE-2021-3374 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
Directory traversal in RStudio Shiny Server before 1.5.16 allows attackers to read the application source code, involving an encoded slash.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMRstudio Shiny Server <1.5.16 - Local File InclusionCVSS 5.3
Rstudio Shiny Server prior to 1.5.16 is vulnerable to local file inclusion and source code leakage. This can be exploited by appending an encoded slash to the URL.
Impact
Successful exploitation of this vulnerability could allow an attacker to read arbitrary files on the server, potentially exposing sensitive information.
Remediation
Upgrade Rstudio Shiny Server to version 1.5.16 or later to mitigate the vulnerability.
WeaknessesCWE-22
Authorsgeeknik
Template tagscve2021cverstudiotraversalvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:rstudio:shiny_server:*:*:*:*:pro:*:*:*
https://github.com/colemanjp/shinyserver-directory-traversal-source-code-leak https://blog.rstudio.com/2021/01/13/shiny-server-1-5-16-update/ https://nvd.nist.gov/vuln/detail/CVE-2021-3374 https://github.com/ARPSyndicate/cvemon https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
3github.com
https://github.com/colemanjp/shinyserver-directory-traversal-source-code-leak nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-3374