Record summary

CVE-2022-27043 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

Yearning versions 2.3.1 and 2.3.2 Interstellar GA and 2.3.4 - 2.3.6 Neptune is vulnerable to Directory Traversal.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHYearning - Directory TraversalCVSS 7.5

Yearning has a directory traversal vulnerability that can be exploited by attackers to obtain sensitive information. The vulnerability is present in multiple versions of Yearning.

Impact

Unauthenticated attackers can exploit directory traversal to read arbitrary files from the Yearning database management system, potentially accessing sensitive configuration files, credentials, and SQL audit logs.

Remediation

Update Yearning to a patched version that properly validates file paths and prevents directory traversal attacks through the front endpoint.

WeaknessesCWE-22
AuthorsCo5mos
Template tagscvecve2022yearninglfivuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:yearning:yearning:*:*:*:*:*:*:*:*
FOFA: app="Yearning"

Source: ProjectDiscovery

References

2