github.com
https://github.com/litespeedtech/openlitespeed/blob/v1.7.16.1/src/main/httpserver.cpp CVE-2022-0072
MEDIUM
Directory Traversal in OpenLiteSpeed Web Server
Record summary
CVE-2022-0072 has a selected CVSS score of 5.8 (medium).
Description
Directory Traversal vulnerability in LiteSpeed Technologies OpenLiteSpeed Web Server and LiteSpeed Web Server dashboards allows Path Traversal. This affects versions from 1.5.11 through 1.5.12, from 1.6.5 through 1.6.20.1, from 1.7.0 before 1.7.16.1
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated May 9, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
LiteSpeed Web ServerBrowse LiteSpeed Technologies / LiteSpeed Web ServerDefault status: unaffected | CVE List | 1.5.11 to ≤ 1.5.12 | affected |
| 1.6.5 to ≤ 1.6.20.1 | affected | ||
| 1.7.0 to < 1.7.16.1 | affected | ||
OpenLiteSpeed Web ServerBrowse LiteSpeed Technologies / OpenLiteSpeed Web ServerDefault status: unaffected | CVE List | 1.5.11 to ≤ 1.5.12 | affected |
| 1.6.5 to ≤ 1.6.20.1 | affected | ||
| 1.7.0 to < 1.7.16.1 | affected |
References
3github.com
https://github.com/litespeedtech/openlitespeed/blob/v1.7.16/src/main/httpserver.cpp nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-0072