The ACME-challenge endpoint in Appwrite 0.5.0 through 0.12.x before 0.12.2 allows remote attackers to read arbitrary local files via ../ directory traversal. In order to be vulnerable, APP_STORAGE_CERTIFICATES/.well-known/acme-challenge must exist on disk. (This pathname is automatically created if the user chooses to install Let's Encrypt certificates via Appwrite.)
CVSS
No CVSS.
References
Configurations
History
03 Apr 2025, 13:17
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/appwrite/appwrite/releases/tag/0.12.2 - Release Notes | |
References | () https://github.com/appwrite/appwrite/pull/2780 - Patch | |
References | () https://dubell.io/unauthenticated-lfi-in-appwrite-0.5.0-0.12.1/ - Exploit | |
References | () https://github.com/appwrite/appwrite/blob/0.12.0/app/controllers/general.php#L539 - Product | |
CPE | cpe:2.3:a:appwrite:appwrite:*:*:*:*:*:*:*:* | |
First Time |
Appwrite appwrite
Appwrite |
22 Feb 2024, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-02-22 22:15
Updated : 2025-04-03 13:17
NVD link : CVE-2022-25377
Mitre link : CVE-2022-25377
JSON object : View
Products Affected
appwrite
- appwrite
CWE
No CWE.