Directory Traversal in st
High severity
GitHub Reviewed
Published
Aug 31, 2020
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Aug 31, 2020
Last updated
Jan 9, 2023
Versions of
st
prior to 0.2.5 are affected by a directory traversal vulnerability. Vulnerable versions fail to properly handle URL encoded dots, which caused%2e
to be interpreted as.
by the filesystem, resulting the potential for an attacker to read sensitive files on the server.Recommendation
Update to version 0.2.5 or later.
References