www.vulncheck.com Path Traversal Vulnerabilities in Knowns Affecting Multiple Versions
Article Content
- •Two path traversal vulnerabilities identified in Knowns software.
- •Affected versions include those before 0.30.0 and 0.33.0 and later.
- •No active exploitation confirmed, but immediate patching is recommended.
Two path traversal vulnerabilities have been identified in the Knowns software. The first vulnerability affects versions before 0.30.0, while the second affects versions 0.33.0 and later. Both vulnerabilities are categorized under CWE-22, which pertains to improper limitations of pathnames. Attackers can exploit these vulnerabilities via the Document API and Template Engine, potentially allowing unauthorized access to sensitive files. The vulnerabilities have been documented in GitHub Security Advisories (GHSA-3h35-4jq7-hv45 and GHSA-68cq-4rwm-f7jr). Users of affected versions are advised to prioritize patching to mitigate risks. No active exploitation has been confirmed as of now, but the vulnerabilities are significant enough to warrant immediate attention. The advisories provide guidance on vulnerability prioritization and early warning systems for ongoing threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Multiple CVEs Expose Vulnerabilities in Cybersecurity Tools and Applications A series of vulnerabilities have been reported affecting various cybersecurity tools and applications. Notable among them is CVE-2024-51482, a blind SQL injection vulnerability in ZoneMinder, allowing attackers to execute arbitrary SQL commands on the database server. CVE-2026-22557, a path traversal vulnerability in…