{"id":"CVE-2022-4773","summary":"cloudsync LocalFilesystemConnector.java getItem path traversal","details":"** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in cloudsync. Affected by this vulnerability is the function getItem of the file src/main/java/cloudsync/connector/LocalFilesystemConnector.java. The manipulation leads to path traversal. It is possible to launch the attack on the local host. The name of the patch is 3ad796833398af257c28e0ebeade68518e0e612a. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216919. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.","modified":"2026-08-12T13:33:35.062783Z","published":"2022-12-27T23:05:37.534Z","database_specific":{"cwe_ids":["CWE-22"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/4xxx/CVE-2022-4773.json","cna_assigner":"VulDB"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/4xxx/CVE-2022-4773.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-4773"},{"type":"ADVISORY","url":"https://vuldb.com/?id.216919"},{"type":"REPORT","url":"https://vuldb.com/?ctiid.216919"},{"type":"FIX","url":"https://github.com/HolgerHees/cloudsync/commit/3ad796833398af257c28e0ebeade68518e0e612a"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/holgerhees/cloudsync","events":[{"introduced":"0"},{"fixed":"3ad796833398af257c28e0ebeade68518e0e612a"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v1.0-beta14","v1.0-beta12","v1.0-beta11","v1.0-beta10","v1.0-beta9","v1.0-beta8","v1.0-beta7","v1.0-beta6","v1.0-beta5","v1.0-beta4","v1.0-beta3","v1.0-beta2","v1.0-beta1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-4773.json","vanir_signatures_modified":"2026-08-12T13:33:35Z","vanir_signatures":[{"digest":{"function_hash":"109783577688533687957683343273447491471","length":4064},"id":"CVE-2022-4773-40ced546","signature_type":"Function","signature_version":"v1","source":"https://github.com/holgerhees/cloudsync/commit/3ad796833398af257c28e0ebeade68518e0e612a","target":{"file":"src/main/java/cloudsync/connector/LocalFilesystemConnector.java","function":"getItem"},"deprecated":false},{"digest":{"line_hashes":["89420516857254812841816402803818866145","92420760527762796989155655024272266546","242475902173834287261730207130887936764","250370438620134956514027567194699495224"],"threshold":0.9},"id":"CVE-2022-4773-a8313621","signature_type":"Line","signature_version":"v1","source":"https://github.com/holgerhees/cloudsync/commit/3ad796833398af257c28e0ebeade68518e0e612a","target":{"file":"src/main/java/cloudsync/connector/LocalFilesystemConnector.java"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}