CVE-2024-22050

HIGH

Iodine < 0.7.33 - Unauthenticated Path Traversal via Static File Service

Title source: llm
STIX 2.1

Description

Path traversal in the static file service in Iodine less than 0.7.33 allows an unauthenticated, remote attacker to read files outside the public folder via malicious URLs.

Scores

CVSS v3 7.5
EPSS 0.0034
EPSS Percentile 56.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
boazsegev/iodine < 0.7.33
rubygems/iodine 0 - 0.7.34RubyGems
Published Jan 04, 2024
Tracked Since Feb 18, 2026