<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T09:30:30.284110+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2023-49793</id>
    <title>CVE-2023-49793 — Path traversal in `CodeChecker server` in the endpoint of `CodeChecker store`</title>
    <updated>2026-10-04T09:30:30.285903+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ericsson codechecker</p>
<p>CodeChecker is an analyzer tooling, defect database and viewer extension for the Clang Static Analyzer and Clang Tidy. Zip files uploaded to the server endpoint of `CodeChecker store` are not properly sanitized. An attacker, using a path traversal attack, can load and display files on the machine of `CodeChecker server`. The vulnerable endpoint is `/Default/v6.53/CodeCheckerService@massStoreRun`. The path traversal vulnerability allows reading data on the machine of the `CodeChecker server`, with the same permission level as the `CodeChecker server`.
The attack requires a user account on the `CodeChecker server`, with permission to store to a server, and view the stored report. This vulnerability has been patched in version 6.23.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2023-49793"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h26w-r4m5-8rrf</id>
    <title>GHSA-h26w-r4m5-8rrf — CodeChecker has a Path traversal in `CodeChecker server` in the endpoint of `CodeChecker store`</title>
    <updated>2026-10-04T09:30:30.285961+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: codechecker</p>
<p>## Summary</p>
<p>ZIP files uploaded to the server-side endpoint handling a `CodeChecker store` are not properly sanitized. An attacker can exercise a path traversal to make the `CodeChecker server` load and display files from an arbitrary location on the server machine.</p>
<p>## Details</p>
<p>### Target</p>
<p>The vulnerable endpoint is `/&lt;PRODUCT_URL&gt;/v6.53/CodeCheckerService@massStoreRun`.</p>
<p>### Exploit overview</p>
<p>The attack is made possible by improper sanitization at one point in the process.</p>
<p>1. When the ZIP file is uploaded by `CodeChecker store`, it is first unzipped to a temporary directory (safely).
2. When deciding which files to insert into CodeChecker's internal database, the decision is made based on the `content_hashes.json` in the ZIP. An attacker has control over the contents of this file.
3. After reading that file, the paths specified in the JSON are normalized by this code:
https://github.com/Ericsson/codechecker/blob/fa41e4e5d9566b5a4f5a80a27bddec73a5146f5a/web/server/codechecker_server/api/mass_store_run.py#L442-L444
4. Providing sufficiently many `../../`s inside the `content_hashes.json`, an attacker can control the insertion of completely arbitrary files into CodeChecker's internal database.
5. This is confirmed in the log output:
```
mass_store_run.py:444 __store_source_files() - Storing source file: /etc/passwd
```
6. Once the file is inserted into the internal database, it can be displayed trivially on the Web interface.
As CodeChecker doesn't distinguish between filenam…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h26w-r4m5-8rrf"/>
  </entry>
</feed>
