Skip to content

Path Traversal on Nginx frontend

Moderate
Naramsim published GHSA-24vh-6cjj-7jxc Oct 29, 2021

Package

No package listed

Affected versions

2.2.0

Patched versions

2.3.0

Description

Impact

Users who run PokeAPI on the public Internet might suffer from a Path Traversal vulnerability on the Nginx container that proxies PokeAPI. The only data that an attacker might see is the filesystem of the container itself. The only sensitive information an attacker could see is thus the SSL certificate and its key that Nginx is currently exposing.

Patches

2.3.0

Workarounds

Manually patch the Nginx conf

References

#665

Severity

Moderate
5.3
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
Low
Privileges required
None
User interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVE ID

No known CVE

Weaknesses

Credits