CVE-2022-27043
Yearning - Directory Traversal
Record summary
CVE-2022-27043 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Yearning versions 2.3.1 and 2.3.2 Interstellar GA and 2.3.4 - 2.3.6 Neptune is vulnerable to Directory Traversal.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHYearning - Directory TraversalCVSS 7.5
Yearning has a directory traversal vulnerability that can be exploited by attackers to obtain sensitive information. The vulnerability is present in multiple versions of Yearning.
Impact
Unauthenticated attackers can exploit directory traversal to read arbitrary files from the Yearning database management system, potentially accessing sensitive configuration files, credentials, and SQL audit logs.
Remediation
Update Yearning to a patched version that properly validates file paths and prevents directory traversal attacks through the front endpoint.
Source: ProjectDiscovery