Loading HuntDB...

GHSA-8mwh-2jgw-x22m

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.

By abusing this vulnerability, it is possible to steal session cookies of other active users.

Related CVEs

Key Information

GHSA ID
GHSA-8mwh-2jgw-x22m
Published
January 10, 2024 12:30 PM
Last Modified
January 16, 2024 9:31 PM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: August 1, 2025 6:44 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.