CVE-2020-15101Low· 2.8▾ Sunlitfreewvs's nested directory structure can interrupt scan
▾ Sunlit zone — Low / medium · no exploitation signal
impact 15.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.6%
0.6% → 0.7%
A directory structure of more than 1000 nested directories can interrupt a freewvs scan due to Python's recursion limit and os.walk(). This can be problematic in a case where an administrator scans the dirs of potentially untrusted users.
This has been fixed in this commit by limiting the recursion to 500 directories: https://github.com/schokokeksorg/freewvs/commit/83a6b55c0435c69f447488b791555e6078803143
This issue was discovered by Hanno Böck.
freewvs < 0.1.1Upgrade to a patched release:
freewvs 0.1.1Connected by shared product, vendor, weakness, or advisory.