CVE-2021-40978

high

Description

The mkdocs 1.2.2 built-in dev-server allows directory traversal using the port 8000, enabling remote exploitation to obtain :sensitive information. NOTE: the vendor has disputed this as described in https://github.com/mkdocs/mkdocs/issues/2601.] and https://github.com/nisdn/CVE-2021-40978/issues/1

References

https://github.com/nisdn/CVE-2021-40978/issues/1

https://github.com/nisdn/CVE-2021-40978

https://github.com/mkdocs/mkdocs/issues/2601

https://github.com/mkdocs/mkdocs

Details

Source: Mitre, NVD

Published: 2021-10-07

Updated: 2024-11-21

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Severity: High