CVE-2022-25377

The ACME-challenge endpoint in Appwrite 0.5.0 through 0.12.x before 0.12.2 allows remote attackers to read arbitrary local files via ../ directory traversal. In order to be vulnerable, APP_STORAGE_CERTIFICATES/.well-known/acme-challenge must exist on disk. (This pathname is automatically created if the user chooses to install Let's Encrypt certificates via Appwrite.)
Configurations

Configuration 1 (hide)

cpe:2.3:a:appwrite:appwrite:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-02-22 22:15

Updated : 2025-04-03 13:17


NVD link : CVE-2022-25377

Mitre link : CVE-2022-25377

CVE.ORG link : CVE-2022-25377


JSON object : View

Products Affected

appwrite

  • appwrite
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')