8.7 HIGH
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): High (H)
- Vulnerable System Impact Integrity (VI): None (N)
- Vulnerable System Impact Availability (VA): None (N)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Automatable (AU): Yes (Y)
- Recovery (R): Automatic (A)
- Value Density (V): Diffuse (D)
- Vulnerability Response Effort (RE): Moderate (M)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): High (H)
- Modified Vulnerable System Impact Integrity (MVI): None (N)
- Modified Vulnerable System Impact Availability (MVA): None (N)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
Activity log
- Created suggestion
The cohttp package before 6.3.0 for OCaml allows directory traversal.
The cohttp package before 6.3.0 for OCaml allows directory traversal.
Affected products
- <6.3.0
Matching in nixpkgs
pkgs.ocamlPackages.cohttp
HTTP(S) library for Lwt, Async and Mirage
pkgs.ocamlPackages.cohttp-eio
CoHTTP implementation with eio backend
pkgs.ocamlPackages.cohttp-lwt
CoHTTP implementation using the Lwt concurrency library
pkgs.ocamlPackages.cohttp-top
CoHTTP toplevel pretty printers for HTTP types
pkgs.ocamlPackages.cohttp_5_3
HTTP(S) library for Lwt, Async and Mirage
pkgs.ocamlPackages.paf-cohttp
CoHTTP client with its HTTP/AF implementation
pkgs.ocamlPackages.cohttp-async
CoHTTP implementation for the Async concurrency library
pkgs.ocamlPackages_latest.cohttp
HTTP(S) library for Lwt, Async and Mirage
pkgs.ocamlPackages.cohttp-lwt_5_3
CoHTTP implementation using the Lwt concurrency library
pkgs.ocamlPackages.graphql-cohttp
Run GraphQL servers with “cohttp”
pkgs.ocamlPackages.cohttp-lwt-jsoo
CoHTTP implementation for the Js_of_ocaml JavaScript compiler
pkgs.ocamlPackages.cohttp-lwt-unix
CoHTTP implementation for Unix and Windows using Lwt
pkgs.ocamlPackages.cohttp-async_5_3
CoHTTP implementation for the Async concurrency library
pkgs.ocamlPackages_latest.cohttp-eio
CoHTTP implementation with eio backend
pkgs.ocamlPackages_latest.cohttp-lwt
CoHTTP implementation using the Lwt concurrency library
pkgs.ocamlPackages_latest.cohttp-top
CoHTTP toplevel pretty printers for HTTP types
pkgs.ocamlPackages_latest.cohttp_5_3
HTTP(S) library for Lwt, Async and Mirage
pkgs.ocamlPackages_latest.paf-cohttp
CoHTTP client with its HTTP/AF implementation
pkgs.ocamlPackages_latest.cohttp-async
CoHTTP implementation for the Async concurrency library
pkgs.ocamlPackages.cohttp_static_handler
Library for easily creating a cohttp handler for static files
pkgs.ocamlPackages_latest.cohttp-lwt_5_3
CoHTTP implementation using the Lwt concurrency library
pkgs.ocamlPackages_latest.graphql-cohttp
Run GraphQL servers with “cohttp”
pkgs.ocamlPackages.cohttp-server-lwt-unix
Lightweight Cohttp + Lwt based HTTP server
pkgs.ocamlPackages.cohttp_async_websocket
Websocket library for use with cohttp and async
pkgs.ocamlPackages_latest.cohttp-lwt-jsoo
CoHTTP implementation for the Js_of_ocaml JavaScript compiler
pkgs.ocamlPackages_latest.cohttp-lwt-unix
CoHTTP implementation for Unix and Windows using Lwt
pkgs.ocamlPackages_latest.cohttp-async_5_3
CoHTTP implementation for the Async concurrency library
pkgs.ocamlPackages_latest.cohttp_static_handler
Library for easily creating a cohttp handler for static files
pkgs.ocamlPackages_latest.cohttp-server-lwt-unix
Lightweight Cohttp + Lwt based HTTP server
pkgs.ocamlPackages_latest.cohttp_async_websocket
Websocket library for use with cohttp and async
pkgs.ocamlPackages.janeStreet.cohttp_static_handler
Library for easily creating a cohttp handler for static files
pkgs.ocamlPackages.janeStreet.cohttp_async_websocket
Websocket library for use with cohttp and async
pkgs.ocamlPackages_latest.janeStreet.cohttp_static_handler
Library for easily creating a cohttp handler for static files
Package maintainers
-
@vbgl Vincent Laporte <Vincent.Laporte@gmail.com>
-
@sternenseemann Lukas Epple <sternenseemann@systemli.org>