Uncontrolled Search Path Element in GitHub repository bits-and-blooms/bloom prior to 3.3.1.
The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Link | Tags |
---|---|
https://huntr.dev/bounties/cab50e44-0995-4ac1-a5d5-889293b9704f | exploit third party advisory patch |
https://github.com/bits-and-blooms/bloom/commit/658f1393d4c52254a3d22f5f64f217405ec5fefb | third party advisory patch |