CVE-2023-40274
Description
An issue was discovered in zola 0.13.0 through 0.17.2. The custom implementation of a web server, available via the "zola serve" command, allows directory traversal. The handle_request function, used by the server to process HTTP requests, does not account for sequences of special path control characters (../) in the URL when serving a file, which allows one to escape the webroot of the server and read arbitrary files from the filesystem.
Related CPE's
Could not find any relations
CvssV3 impact
Could not find any metrics
CvssV2 impact
Could not find any metrics