This is a summary of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis โ
Q1What is this vulnerability? (Essence + Consequences)
๐จ **Essence**: Directory Traversal in Bazarr v1.4.3. ๐ **Consequences**: Unauthenticated attackers can read arbitrary files (e.g., /etc/passwd). Critical data leak risk! ๐
Q2Root Cause? (CWE/Flaw)
๐ก๏ธ **Root Cause**: Lack of input validation on filename parameters. ๐ **Flaw**: Allows path traversal sequences (`../`) to escape the intended directory. CWE-22 equivalent. ๐
Q3Who is affected? (Versions/Components)
๐ฆ **Affected**: Bazarr software. ๐ **Version**: v1.4.3 and prior. ๐ค **Context**: Companion app for Sonarr/Radarr. โ ๏ธ Check your subtitle manager version! ๐
๐ **Threshold**: LOW. ๐ **Auth**: None required. ๐ **Config**: Exposed web interface is enough. Easy to exploit for anyone with network access. ๐ฏ