Home
HIGH: 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
Any version
affected
Description
Lack of user input validation in the file upload functionality of Open Notebook v1.8.3 allows the application user to create or modify files on the docker container via path traversal.
Problem types
CWE-20 Improper input validation
Product status
Any version
Credits
CERT-EU
References
github.com/...tebook/security/advisories/GHSA-x4q2-89g5-594v