CWE-22 · 9 994 записей
Обход каталога
Почему это происходит?
Имя файла, переданное пользователем, объединяется с разрешённым каталогом, но не проверяется, остаётся ли результат внутри этого каталога.
Уязвимый и исправленный код
Показательный учебный пример. Выделенные строки показывают, где ошибка и где исправление.
Уязвимый код
const file = path.join(ROOT, req.query.name);res.sendFile(file);Исправленный код
const file = path.resolve(ROOT, req.query.name);if (!file.startsWith(ROOT + path.sep)) { return res.sendStatus(400);}res.sendFile(file);Как предотвратить
- 01После разрешения пути проверяйте, что он остаётся внутри корневого каталога.
- 02Отдавайте файлы по идентификатору из базы данных, а не по имени.
- 03Запускайте серверный процесс с правом чтения только необходимых каталогов.
CVE этого класса
10 000 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2019-11510Готовый эксплойт | In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attackivanti · connect secure · CWE-22 | Критическая10,0 | KEV | 100,0 % | 8 мая 2019 г. |
99Срочно | CVE-2022-29464Готовый эксплойт | Certain WSO2 products allow unrestricted file upload with resultant remote code execution.wso2 · api manager · CWE-22 | Критическая9,8 | KEV | 100,0 % | 18 апр. 2022 г. |
99Срочно | CVE-2021-22005Готовый эксплойт | The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service.vmware · cloud foundation · CWE-22 | Критическая9,8 | KEV | 100,0 % | 23 сент. 2021 г. |
99Срочно | CVE-2020-5902Готовый эксплойт | In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Intef5 · big-ip access policy manager · CWE-22 | Критическая9,8 | KEV | 100,0 % | 1 июл. 2020 г. |
99Срочно | CVE-2024-23897Готовый эксплойт | Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character follojenkins · jenkins · CWE-22 | Критическая9,8 | KEV | 100,0 % | 24 янв. 2024 г. |
99Срочно | CVE-2019-19781Готовый эксплойт | An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0.citrix · application delivery controller firmware · CWE-22 | Критическая9,8 | KEV | 100,0 % | 27 дек. 2019 г. |
99Срочно | CVE-2018-13379Готовый эксплойт | An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4fortinet · fortiproxy · CWE-22 | Критическая9,8 | KEV | 100,0 % | 4 июн. 2019 г. |
99Срочно | CVE-2021-41773Готовый эксплойт | Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49apache · http server · CWE-22 | Критическая9,8 | KEV | 100,0 % | 5 окт. 2021 г. |
99Срочно | CVE-2021-20090Готовый эксплойт | A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <= buffalo · wsr-2533dhpl2-bk firmware · CWE-22 | Критическая9,8 | KEV | 100,0 % | 29 апр. 2021 г. |
99Срочно | CVE-2021-42013Готовый эксплойт | Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)apache · http server · CWE-22 | Критическая9,8 | KEV | 100,0 % | 7 окт. 2021 г. |
99Срочно | CVE-2024-32113Готовый эксплойт | Apache OFBiz: Path traversal leading to RCEapache · ofbiz · CWE-22 | Критическая9,8 | KEV | 99,9 % | 8 мая 2024 г. |
99Срочно | CVE-2019-3396Готовый эксплойт | The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.1atlassian · confluence server · CWE-22 | Критическая9,8 | KEV | 99,9 % | 25 мар. 2019 г. |
99Срочно | CVE-2021-21972Готовый эксплойт | The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin.vmware · cloud foundation · CWE-22 | Критическая9,8 | KEV | 99,9 % | 24 февр. 2021 г. |
99Срочно | CVE-2010-2861Готовый эксплойт | Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to readobe · coldfusion · CWE-22 | Критическая9,8 | KEV | 99,7 % | 11 авг. 2010 г. |
99Срочно | CVE-2024-4885Готовый эксплойт | WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerabilityprogress · whatsup gold · CWE-22 | Критическая9,8 | KEV | 99,3 % | 25 июн. 2024 г. |
99Срочно | CVE-2019-16278Готовый эксплойт | Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a cnazgul · nostromo nhttpd · CWE-22 | Критическая9,8 | KEV | 99,0 % | 14 окт. 2019 г. |
99Срочно | CVE-2023-47246Готовый эксплойт | In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat wesysaid · sysaid · CWE-22 | Критическая9,8 | KEV | 98,9 % | 10 нояб. 2023 г. |
98Срочно | CVE-2022-41352Готовый эксплойт | An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0.synacor · zimbra collaboration suite · CWE-22 | Критическая9,8 | KEV | 95,5 % | 25 сент. 2022 г. |
97Срочно | CVE-2024-7399Готовый эксплойт | Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attacksamsung · magicinfo 9 server · CWE-22 | Критическая9,8 | KEV | 91,9 % | 12 авг. 2024 г. |
97Срочно | CVE-2022-37042Готовый эксплойт | Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it.synacor · zimbra collaboration suite · CWE-22 | Критическая9,8 | KEV | 91,9 % | 12 авг. 2022 г. |
97Срочно | CVE-2026-85706Готовый эксплойт | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLabgitlab · gitlab · CWE-22 | Критическая10,0 | KEV | 91,4 % | 11 сент. 2026 г. |
96Срочно | CVE-2024-8963Готовый эксплойт | Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.ivanti · endpoint manager cloud services appliance · CWE-22 | Критическая9,1 | KEV | 98,6 % | 19 сент. 2024 г. |
96Срочно | CVE-2025-34028Готовый эксплойт | Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversalcommvault · commvault · CWE-22 | Критическая9,3 | KEV | 97,6 % | 22 апр. 2025 г. |
96Срочно | CVE-2019-7195Готовый эксплойт | This external control of file name or path vulnerability allows remote attackers to access or modify system files.qnap · photo station · CWE-22 | Критическая9,8 | KEV | 89,7 % | 5 дек. 2019 г. |
95Срочно | CVE-2024-41713Готовый эксплойт | A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthentimitel · micollab · CWE-22 | Критическая9,1 | KEV | 98,1 % | 21 окт. 2024 г. |
- CVE-2019-11510100Срочно
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attack
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %ivanti · connect secure8 мая 2019 г.
- CVE-2022-2946499Срочно
Certain WSO2 products allow unrestricted file upload with resultant remote code execution.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %wso2 · api manager18 апр. 2022 г.
- CVE-2021-2200599Срочно
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %vmware · cloud foundation23 сент. 2021 г.
- CVE-2020-590299Срочно
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Inte
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %f5 · big-ip access policy manager1 июл. 2020 г.
- CVE-2024-2389799Срочно
Jenkins 2.441 and earlier, LTS 2.426.2 and earlier does not disable a feature of its CLI command parser that replaces an '@' character follo
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %jenkins · jenkins24 янв. 2024 г.
- CVE-2019-1978199Срочно
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %citrix · application delivery controller firmware27 дек. 2019 г.
- CVE-2018-1337999Срочно
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %fortinet · fortiproxy4 июн. 2019 г.
- CVE-2021-4177399Срочно
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · http server5 окт. 2021 г.
- CVE-2021-2009099Срочно
A path traversal vulnerability in the web interfaces of Buffalo WSR-2533DHPL2 firmware version <= 1.02 and WSR-2533DHP3 firmware version <=
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %buffalo · wsr-2533dhpl2-bk firmware29 апр. 2021 г.
- CVE-2021-4201399Срочно
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · http server7 окт. 2021 г.
- CVE-2024-3211399Срочно
Apache OFBiz: Path traversal leading to RCE
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %apache · ofbiz8 мая 2024 г.
- CVE-2019-339699Срочно
The Widget Connector macro in Atlassian Confluence Server before version 6.6.12 (the fixed version for 6.6.x), from version 6.7.0 before 6.1
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %atlassian · confluence server25 мар. 2019 г.
- CVE-2021-2197299Срочно
The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %vmware · cloud foundation24 февр. 2021 г.
- CVE-2010-286199Срочно
Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to re
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %adobe · coldfusion11 авг. 2010 г.
- CVE-2024-488599Срочно
WhatsUp Gold GetFileWithoutZip Directory Traversal Remote Code Execution Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %progress · whatsup gold25 июн. 2024 г.
- CVE-2019-1627899Срочно
Directory Traversal in the function http_verify in nostromo nhttpd through 1.9.6 allows an attacker to achieve remote code execution via a c
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %nazgul · nostromo nhttpd14 окт. 2019 г.
- CVE-2023-4724699Срочно
In SysAid On-Premise before 23.3.36, a path traversal vulnerability leads to code execution after an attacker writes a file to the Tomcat we
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %sysaid · sysaid10 нояб. 2023 г.
- CVE-2022-4135298Срочно
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15 and 9.0.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %synacor · zimbra collaboration suite25 сент. 2022 г.
- CVE-2024-739997Срочно
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1050 allows attack
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %samsung · magicinfo 9 server12 авг. 2024 г.
- CVE-2022-3704297Срочно
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts files from it.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %synacor · zimbra collaboration suite12 авг. 2022 г.
- CVE-2026-8570697Срочно
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 91 %gitlab · gitlab11 сент. 2026 г.
- CVE-2024-896396Срочно
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 99 %ivanti · endpoint manager cloud services appliance19 сент. 2024 г.
- CVE-2025-3402896Срочно
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 98 %commvault · commvault22 апр. 2025 г.
- CVE-2019-719596Срочно
This external control of file name or path vulnerability allows remote attackers to access or modify system files.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 90 %qnap · photo station5 дек. 2019 г.
- CVE-2024-4171395Срочно
A vulnerability in the NuPoint Unified Messaging (NPM) component of Mitel MiCollab through 9.8 SP1 FP2 (9.8.1.201) could allow an unauthenti
КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 98 %mitel · micollab21 окт. 2024 г.