Vulnerability Description
A vulnerability exists in gowitness < 2.3.6 that allows an unauthenticated attacker to perform an arbitrary file read using the file:// scheme in the url parameter to get an image of any file.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Sensepost | Gowitness | < 2.3.6 |
Related Weaknesses (CWE)
References
- https://github.com/sensepost/gowitness/releases/tag/2.3.6PatchRelease NotesThird Party Advisory
- https://twitter.com/leonjza/status/1395283512433971202?s=19Third Party Advisory
- https://github.com/sensepost/gowitness/releases/tag/2.3.6PatchRelease NotesThird Party Advisory
- https://twitter.com/leonjza/status/1395283512433971202?s=19Third Party Advisory
FAQ
What is CVE-2021-33359?
CVE-2021-33359 is a vulnerability with a CVSS score of 7.5 (HIGH). A vulnerability exists in gowitness < 2.3.6 that allows an unauthenticated attacker to perform an arbitrary file read using the file:// scheme in the url parameter to get an image of any file.
How severe is CVE-2021-33359?
CVE-2021-33359 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-33359?
Check the references section above for vendor advisories and patch information. Affected products include: Sensepost Gowitness.