An issue was discovered in Pascom Cloud Phone System before 7.20.x. A configuration error between NGINX and a backend Tomcat server leads to a path traversal in the Tomcat server, exposing unintended endpoints.
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Link | Tags |
---|---|
https://www.pascom.net/doc/en/release-notes/ | release notes vendor advisory |
https://www.pascom.net/doc/en/release-notes/pascom19/ | release notes vendor advisory |
https://kerbit.io/research/read/blog/4 | patch third party advisory exploit |
https://tutorialboy24.blogspot.com/2022/03/the-story-of-3-bugs-that-lead-to.html | patch third party advisory exploit |