Vulnerability Description
An attacker can include file contents from outside the `/adapter/xxx/` directory, where `xxx` is the name of an existent adapter like "admin". It is exploited using the administrative web panel with a request for an adapter file. **Note:** The attacker has to be logged in if the authentication is enabled (by default isn't enabled).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Iobroker | Iobroker.Js-Controller | < 2.0.25 |
Related Weaknesses (CWE)
References
- https://github.com/ioBroker/ioBroker.js-controller/commit/f6e292c6750a491a5000d0PatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-IOBROKERJSCONTROLLER-534881ExploitThird Party Advisory
- https://github.com/ioBroker/ioBroker.js-controller/commit/f6e292c6750a491a5000d0PatchThird Party Advisory
- https://snyk.io/vuln/SNYK-JS-IOBROKERJSCONTROLLER-534881ExploitThird Party Advisory
FAQ
What is CVE-2019-10767?
CVE-2019-10767 is a vulnerability with a CVSS score of 7.5 (HIGH). An attacker can include file contents from outside the `/adapter/xxx/` directory, where `xxx` is the name of an existent adapter like "admin". It is exploited using the administrative web panel with a...
How severe is CVE-2019-10767?
CVE-2019-10767 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-10767?
Check the references section above for vendor advisories and patch information. Affected products include: Iobroker Iobroker.Js-Controller.