← Back

CVE-2018-17567

nvd nist
Published: Sep 28, 2018Modified: Nov 21, 2024

JSON object

Loading...
7.5
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Jekyll through 3.6.2, 3.7.x through 3.7.3, and 3.8.x through 3.8.3 allows attackers to access arbitrary files by specifying a symlink in the "include" key in the "_config.yml" file.

Affected (3)

Products: Jekyllrb: Jekyll
1 product
Jekyll
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Jekyllrb
Up to 3.6.2
From 3.7.0 to 3.7.3
From 3.8.0 to 3.8.3

Timeline

No history available yet.