GHSA-qg5v-jw6f-rpfj
Dashboard / Vulnerabilities / GHSA-qg5v-jw6f-rpfj
Summary: SabreDAV Directory Traversal vulnerability
Details: The HTML\Browser plugin in SabreDAV before 1.6.9, 1.7.x before 1.7.7, and 1.8.x before 1.8.5, as used in ownCloud, when running on Windows, does not properly check path separators in the base path, which allows remote attackers to read arbitrary files via a `\` (backslash) character.
References: https://nvd.nist.gov/vuln/detail/CVE-2013-1939, https://github.com/FriendsOfPHP/security-advisories/blob/master/sabre/dav/CVE-2013-1939.yaml, https://github.com/sabre-io/dav, https://groups.google.com/forum/?fromgroups=#!topic/sabredav-discuss/ehOUu7wTSGQ, https://groups.google.com/forum/?fromgroups=#%21topic/sabredav-discuss/ehOUu7wTSGQ, http://owncloud.org/about/security/advisories/oC-SA-2013-016
Affected packages
Package
Name: sabre/dav
Purl: pkg:composer/sabre/dav
Affected ranges
Type: ECOSYSTEM
Events:
