CVE-2022-45921

HIGH

FusionAuth < 1.41.3 - Path Traversal and Arbitrary File Read

Title source: llm
STIX 2.1

Description

FusionAuth before 1.41.3 allows a file outside of the application root to be viewed or retrieved using an HTTP request. To be specific, an attacker may be able to view or retrieve any file readable by the user running the FusionAuth process.

References (2)

Core 2
Core References
Release Notes, Vendor Advisory
https://fusionauth.io/docs/v1/tech/release-notes

Scores

CVSS v3 7.5
EPSS 0.0067
EPSS Percentile 47.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
fusionauth/fusionauth 1.37.0 - 1.41.3
io.fusionauth/fusionauth-java-client 1.37.0 - 1.41.3Maven
Published Nov 28, 2022
Tracked Since Feb 18, 2026