Vulnerabilities/

Arbitrary File Write in iobroker.admin

Severity:
High

Description

Versions of iobroker.admin prior to 3.6.12 are vulnerable to Path Traversal. The package fails to restrict access to folders outside of the intended folder in the /log/ route, which may allow attackers to include arbitrary files in the system.

Recommendation

Update the iobroker.admin package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
iobroker.admin
Anything's wrong? Let us know Last updated on January 09, 2023