CWE-552
AllowedFiles or Directories Accessible to External Parties
Abstraction: Base · Status: Draft
The product makes files or directories accessible to unauthorized actors, even though they should not be.
730 vulnerabilities reference this CWE, most recent first.
GHSA-VW7P-RWG9-7MRQ
Vulnerability from github – Published: 2025-05-12 21:31 – Updated: 2025-05-12 21:31A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links, the server could unintentionally show incorporate and make visible content from outside the git repo.
{
"affected": [],
"aliases": [
"CVE-2024-4981"
],
"database_specific": {
"cwe_ids": [
"CWE-552"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2025-05-12T19:15:47Z",
"severity": "HIGH"
},
"details": "A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links, the server could unintentionally show incorporate and make visible content from outside the git repo.",
"id": "GHSA-vw7p-rwg9-7mrq",
"modified": "2025-05-12T21:31:09Z",
"published": "2025-05-12T21:31:09Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4981"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2024-4981"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2278745"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2280723"
},
{
"type": "WEB",
"url": "https://pagure.io/pagure/c/454f2677bc50d7176f07da9784882eb2176537f4"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L",
"type": "CVSS_V3"
}
]
}
GHSA-VXF8-WWPW-PHXG
Vulnerability from github – Published: 2023-05-12 12:30 – Updated: 2024-03-21 03:35An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to access sensitive information via the EXE installer.
{
"affected": [],
"aliases": [
"CVE-2023-29820"
],
"database_specific": {
"cwe_ids": [
"CWE-552",
"CWE-668"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-05-12T11:15:12Z",
"severity": "MODERATE"
},
"details": "An issue found in Webroot SecureAnywhere Endpoint Protection CE 23.1 v.9.0.33.39 and before allows a local attacker to access sensitive information via the EXE installer.",
"id": "GHSA-vxf8-wwpw-phxg",
"modified": "2024-03-21T03:35:15Z",
"published": "2023-05-12T12:30:19Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-29820"
},
{
"type": "WEB",
"url": "https://www.spenceralessi.com/CVEs/2023-05-10-Webroot-SecureAnywhere"
},
{
"type": "WEB",
"url": "http://secureanywhere.com"
},
{
"type": "WEB",
"url": "http://webroot.com"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-VXXR-CWRH-FF4M
Vulnerability from github – Published: 2022-05-24 19:11 – Updated: 2022-05-24 19:11In gitit before 0.15.0.0, the Export feature can be exploited to leak information from files.
{
"affected": [],
"aliases": [
"CVE-2021-38711"
],
"database_specific": {
"cwe_ids": [
"CWE-552"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2021-08-16T04:15:00Z",
"severity": "HIGH"
},
"details": "In gitit before 0.15.0.0, the Export feature can be exploited to leak information from files.",
"id": "GHSA-vxxr-cwrh-ff4m",
"modified": "2022-05-24T19:11:19Z",
"published": "2022-05-24T19:11:19Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-38711"
},
{
"type": "WEB",
"url": "https://github.com/jgm/gitit/commit/eed32638f4f6e3b2f4b8a9a04c4b72001acf9ad8"
},
{
"type": "WEB",
"url": "https://github.com/jgm/gitit/compare/0.14.0.0...0.15.0.0"
}
],
"schema_version": "1.4.0",
"severity": []
}
GHSA-W2Q4-JGF9-7P93
Vulnerability from github – Published: 2026-09-23 00:31 – Updated: 2026-09-23 00:31IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of build context directories into container images.
{
"affected": [],
"aliases": [
"CVE-2026-15915"
],
"database_specific": {
"cwe_ids": [
"CWE-552"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-09-22T22:17:06Z",
"severity": "MODERATE"
},
"details": "IBM Concert 1.0.0 through 3.0.0 could allow a local attacker to obtain sensitive information due to recursive copying of build context directories into container images.",
"id": "GHSA-w2q4-jgf9-7p93",
"modified": "2026-09-23T00:31:13Z",
"published": "2026-09-23T00:31:13Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-15915"
},
{
"type": "WEB",
"url": "https://www.ibm.com/support/pages/node/7288830"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-W2W9-635Q-99V6
Vulnerability from github – Published: 2024-07-02 09:32 – Updated: 2024-07-02 09:32Web services managed by Edito CMS (Content Management System) in versions from 3.5 through 3.25 leak sensitive data as they allow downloading configuration files by an unauthenticated user. The issue in versions 3.5 - 3.25 was removed in releases which dates from 10th of January 2014. Higher versions were never affected.
{
"affected": [],
"aliases": [
"CVE-2024-4836"
],
"database_specific": {
"cwe_ids": [
"CWE-552"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2024-07-02T09:15:19Z",
"severity": "HIGH"
},
"details": "Web services managed by Edito CMS (Content Management System) in versions from 3.5 through 3.25 leak sensitive data as they allow downloading configuration files by an unauthenticated user.\nThe issue in versions 3.5 - 3.25 was removed in releases which dates from 10th of January 2014. Higher versions were never affected.",
"id": "GHSA-w2w9-635q-99v6",
"modified": "2024-07-02T09:32:07Z",
"published": "2024-07-02T09:32:07Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2024-4836"
},
{
"type": "WEB",
"url": "https://cert.pl/en/posts/2024/07/CVE-2024-4836"
},
{
"type": "WEB",
"url": "https://cert.pl/posts/2024/07/CVE-2024-4836"
},
{
"type": "WEB",
"url": "https://www.edito.pl"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-W36W-37XX-85WG
Vulnerability from github – Published: 2023-09-30 00:31 – Updated: 2023-09-30 00:31A vulnerability was found in Xinhu RockOA 2.3.2. It has been classified as problematic. This affects the function start of the file task.php?m=sys|runt&a=beifen. The manipulation leads to exposure of backup file to an unauthorized control sphere. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-240927.
{
"affected": [],
"aliases": [
"CVE-2023-5297"
],
"database_specific": {
"cwe_ids": [
"CWE-530",
"CWE-552"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-09-29T22:15:12Z",
"severity": "LOW"
},
"details": "A vulnerability was found in Xinhu RockOA 2.3.2. It has been classified as problematic. This affects the function start of the file task.php?m=sys|runt\u0026a=beifen. The manipulation leads to exposure of backup file to an unauthorized control sphere. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-240927.",
"id": "GHSA-w36w-37xx-85wg",
"modified": "2023-09-30T00:31:10Z",
"published": "2023-09-30T00:31:10Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-5297"
},
{
"type": "WEB",
"url": "https://github.com/magicwave18/vuldb/issues/2"
},
{
"type": "WEB",
"url": "https://vuldb.com/?ctiid.240927"
},
{
"type": "WEB",
"url": "https://vuldb.com/?id.240927"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-W4JX-JW2G-XVQV
Vulnerability from github – Published: 2022-05-24 19:09 – Updated: 2022-05-24 19:09In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.
{
"affected": [],
"aliases": [
"CVE-2021-36763"
],
"database_specific": {
"cwe_ids": [
"CWE-552"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2021-08-03T16:15:00Z",
"severity": "HIGH"
},
"details": "In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.",
"id": "GHSA-w4jx-jw2g-xvqv",
"modified": "2022-05-24T19:09:51Z",
"published": "2022-05-24T19:09:51Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-36763"
},
{
"type": "WEB",
"url": "https://customers.codesys.com/index.php?eID=dumpFile\u0026t=f\u0026f=16803\u0026token=0b8edf9276dc39ee52f43026c415c5b38085d90a\u0026download="
}
],
"schema_version": "1.4.0",
"severity": []
}
GHSA-W63G-VJRV-WQJC
Vulnerability from github – Published: 2022-05-18 00:00 – Updated: 2022-05-27 00:01cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file information of the website such as the database configuration file (config / config_database) can be read through this vulnerability.
{
"affected": [],
"aliases": [
"CVE-2021-42644"
],
"database_specific": {
"cwe_ids": [
"CWE-552"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-05-17T12:15:00Z",
"severity": "MODERATE"
},
"details": "cmseasy V7.7.5_20211012 is affected by an arbitrary file read vulnerability. After login, the configuration file information of the website such as the database configuration file (config / config_database) can be read through this vulnerability.",
"id": "GHSA-w63g-vjrv-wqjc",
"modified": "2022-05-27T00:01:09Z",
"published": "2022-05-18T00:00:47Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2021-42644"
},
{
"type": "WEB",
"url": "https://jdr2021.github.io/2021/10/14/CmsEasy_7.7.5_20211012%E5%AD%98%E5%9C%A8%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E5%86%99%E5%85%A5%E5%92%8C%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-W9MP-P2WP-2XF7
Vulnerability from github – Published: 2022-02-10 20:35 – Updated: 2021-04-22 23:05In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.
{
"affected": [
{
"package": {
"ecosystem": "Maven",
"name": "org.apache.tapestry:tapestry-core"
},
"ranges": [
{
"events": [
{
"introduced": "5.4.0"
},
{
"fixed": "5.6.0"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2020-13953"
],
"database_specific": {
"cwe_ids": [
"CWE-552"
],
"github_reviewed": true,
"github_reviewed_at": "2021-04-22T23:05:56Z",
"nvd_published_at": "2020-09-30T18:15:00Z",
"severity": "MODERATE"
},
"details": "In Apache Tapestry from 5.4.0 to 5.5.0, crafting specific URLs, an attacker can download files inside the WEB-INF folder of the WAR being run.",
"id": "GHSA-w9mp-p2wp-2xf7",
"modified": "2021-04-22T23:05:56Z",
"published": "2022-02-10T20:35:42Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2020-13953"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread.html/r37dab61fc7f7088d4311e7f995ef4117d58d86a675f0256caa6991eb@%3Cusers.tapestry.apache.org%3E"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread.html/r50eb12e8a12074a9b7ed63cbab91d180d19cc23dc1da3ed5b6e1280f%40%3Cusers.tapestry.apache.org%3E"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
}
],
"summary": "Improper file downloads in Apache Tapestry"
}
GHSA-WC9M-R3V6-9P5H
Vulnerability from github – Published: 2025-02-04 21:32 – Updated: 2025-02-04 23:18A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.
{
"affected": [
{
"database_specific": {
"last_known_affected_version_range": "\u003c= 2.6.3"
},
"package": {
"ecosystem": "SwiftURL",
"name": "github.com/sparkle-project/Sparkle"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2.6.4"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2025-0509"
],
"database_specific": {
"cwe_ids": [
"CWE-552"
],
"github_reviewed": true,
"github_reviewed_at": "2025-02-04T23:18:58Z",
"nvd_published_at": "2025-02-04T20:15:49Z",
"severity": "HIGH"
},
"details": "A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle\u2019s (Ed)DSA signing checks.",
"id": "GHSA-wc9m-r3v6-9p5h",
"modified": "2025-02-04T23:18:58Z",
"published": "2025-02-04T21:32:28Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0509"
},
{
"type": "WEB",
"url": "https://github.com/sparkle-project/Sparkle/pull/2550"
},
{
"type": "PACKAGE",
"url": "https://github.com/sparkle-project/Sparkle"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20250124-0008"
},
{
"type": "WEB",
"url": "https://sparkle-project.org/documentation/security-and-reliability"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H",
"type": "CVSS_V3"
}
],
"summary": "Sparkle Signing Checks Bypass"
}
Mitigation
When storing data in the cloud (e.g., S3 buckets, Azure blobs, Google Cloud Storage, etc.), use the provider's controls to disable public access.
CAPEC-150: Collect Data from Common Resource Locations
An adversary exploits well-known locations for resources for the purposes of undermining the security of the target. In many, if not most systems, files and resources are organized in a default tree structure. This can be useful for adversaries because they often know where to look for resources or files that are necessary for attacks. Even when the precise location of a targeted resource may not be known, naming conventions may indicate a small area of the target machine's file tree where the resources are typically located. For example, configuration files are normally stored in the /etc director on Unix systems. Adversaries can take advantage of this to commit other types of attacks.
CAPEC-639: Probe System Files
An adversary obtains unauthorized information due to improperly protected files. If an application stores sensitive information in a file that is not protected by proper access control, then an adversary can access the file and search for sensitive information.