CVE-2021-33896

Name
CVE-2021-33896
Description
Dino before 0.1.2 and 0.2.x before 0.2.1 allows Directory Traversal (only for creation of new files) via URI-encoded path separators.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
CONFIRM https://dino.im/security/cve-2021-33896/
MISC https://dino.im/blog/
MLIST http://www.openwall.com/lists/oss-security/2021/06/07/2
FEDORA https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ODN4ZSTBYIW25DO3FNRK6FQRGSYGT57I/
Third Party Advisory https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/P55V3TVSVXREOJAJRXNUSBEUZFOU54V3/

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:dino:dino:*:*:*:*:*:*:*:* dino >= None < 0.1.2
cpe:2.3:a:dino:dino:*:*:*:*:*:*:*:* dino >= 0.2.0 < 0.2.1

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
dino 3.13-community 0.2.1-r0 Galen Abell <galen@galenabell.com> fixed
dino 3.14-community 0.2.1-r0 Galen Abell <galen@galenabell.com> fixed