{"id":"CVE-2021-41323","details":"Directory traversal in the Compress feature in Pydio Cells 2.2.9 allows remote authenticated users to overwrite personal files, or Cells files belonging to any user, via the format parameter.","modified":"2026-07-09T05:45:07.502736Z","published":"2021-09-30T19:15:07.473Z","references":[{"type":"ADVISORY","url":"https://charonv.net/Pydio-Broken-Access-Control/"},{"type":"ADVISORY","url":"https://github.com/pydio/cells/releases/tag/v2.2.12"},{"type":"ADVISORY","url":"https://pydio.com/fr/community/releases/pydio-cells/pydio-cells-enterprise-2212"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pydio/cells","events":[{"introduced":"cf8dab5674c7ec0aa9237b657f006146c9c16f6e"},{"last_affected":"cf8dab5674c7ec0aa9237b657f006146c9c16f6e"},{"fixed":"3cf641708e40fa76ec064b283796d28e831587f2"}],"database_specific":{"cpe":["cpe:2.3:a:pydio:cells:2.2.9:*:*:*:-:*:*:*","cpe:2.3:a:pydio:cells:2.2.9:*:*:*:enterprise:*:*:*"],"extracted_events":[{"introduced":"2.2.9"},{"last_affected":"2.2.9"}],"source":["CPE_STRING","REFERENCES"]}}],"versions":["2.2.9","v2.2.9"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-41323.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N"}]}