漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
kkFileView: Unauthenticated path traversal in POST /listFiles allows arbitrary directory listing
Vulnerability Description
kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated POST /listFiles endpoint in server/src/main/java/cn/keking/web/controller/FileController.java passes the user-controlled path parameter from FileController#getFiles to Files.newDirectoryStream without confinement to the demo directory, allowing directory enumeration outside the intended root. This issue is fixed in version 5.0.1.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Vulnerability Title
kekingcn kkFileView 路径遍历漏洞
Vulnerability Description
kekingcn kkFileView是kekingcn组织的一款文件预览中间件。 kekingcn kkFileView 5.0.1之前版本存在路径遍历漏洞,该漏洞源于未认证的POST /listFiles端点将用户控制的路径参数传递给Files.newDirectoryStream且未限制在demo目录,可能导致目录枚举。
CVSS Information
N/A
Vulnerability Type
N/A