← back
CVE-2024-22050

Iodine Static File Server Path Traversal Vulnerability

CVSS 7.5 HIGHEPSS 0.9%CWE-22
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.5EPSS 0.9%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
04 Jan 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Path traversal in the static file service in Iodine less than 0.7.33 allows an unauthenticated, remote attacker to read files outside the public folder via malicious URLs.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
iodine