{"id":"CVE-2023-49294","summary":"Asterisk Path Traversal vulnerability","details":"Asterisk is an open source private branch exchange and telephony toolkit. In Asterisk prior to versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cert6, it is possible to read any arbitrary file even when the `live_dangerously` is not enabled. This allows arbitrary files to be read. Asterisk versions 18.20.1, 20.5.1, and 21.0.1, as well as certified-asterisk prior to 18.9-cert6, contain a fix for this issue.","aliases":["GHSA-8857-hfmw-vg8f"],"modified":"2026-08-12T14:51:39.397981Z","published":"2023-12-14T19:40:46.157Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-22"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/49xxx/CVE-2023-49294.json"},"references":[{"type":"WEB","url":"https://github.com/asterisk/asterisk/blob/master/main/manager.c#L3757"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2023/12/msg00019.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/49xxx/CVE-2023-49294.json"},{"type":"ADVISORY","url":"https://github.com/asterisk/asterisk/security/advisories/GHSA-8857-hfmw-vg8f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-49294"},{"type":"FIX","url":"https://github.com/asterisk/asterisk/commit/424be345639d75c6cb7d0bd2da5f0f407dbd0bd5"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/asterisk/asterisk","events":[{"introduced":"0"},{"fixed":"14d0e59f3d8f7521621561168ef4a297702d978f"},{"introduced":"de4f63b4824c91a0cd9f3d95f3b7923bec71960c"},{"fixed":"f7a8ac086de697db30e376d589a6f4e17cfabef5"},{"introduced":"12da95e53ff42287ad69d6d5922e06c3d62010ac"},{"fixed":"424be345639d75c6cb7d0bd2da5f0f407dbd0bd5"}],"database_specific":{"cpe":["cpe:2.3:a:digium:asterisk:*:*:*:*:*:*:*:*","cpe:2.3:a:digium:asterisk:21.0.0:*:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:13.13.0:*:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:13.13.0:rc1:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:13.13.0:rc2:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:16.8.0:-:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert1:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert2:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert3:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert4:*:*:*:*:*:*","cpe:2.3:a:sangoma:certified_asterisk:18.9:cert5:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"fixed":"18.20.1"},{"introduced":"19.0.0"},{"fixed":"20.5.1"},{"introduced":"21.0.0"},{"last_affected":"21.0.0"},{"introduced":"13.13.0"},{"last_affected":"13.13.0"},{"introduced":"13.13.0-rc1"},{"last_affected":"13.13.0-rc1"},{"introduced":"13.13.0-rc2"},{"last_affected":"13.13.0-rc2"},{"introduced":"16.8.0-NA"},{"last_affected":"16.8.0-NA"},{"introduced":"18.9-cert1"},{"last_affected":"18.9-cert1"},{"introduced":"18.9-cert2"},{"last_affected":"18.9-cert2"},{"introduced":"18.9-cert3"},{"last_affected":"18.9-cert3"},{"introduced":"18.9-cert4"},{"last_affected":"18.9-cert4"},{"introduced":"18.9-cert5"},{"last_affected":"18.9-cert5"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"]}}],"versions":["13.13.0","13.13.0-rc1","13.13.0-rc2","16.8.0-NA","18.9-cert1","18.9-cert2","18.9-cert3","18.9-cert4","18.9-cert5","21.0.0","= 21.0.0","20.5.0","18.20.0","20.5.0-rc1","18.20.0-rc1","20.4.0","18.19.0","18.19.0-rc2","20.4.0-rc2","20.4.0-rc1","18.19.0-rc1","20.3.1","18.18.1","20.3.0","18.18.0","20.3.0-rc1","18.18.0-rc1","20.2.1","18.17.1","20.2.0","18.17.0","20.2.0-rc1","18.17.0-rc1"],"database_specific":{"vanir_signatures_modified":"2026-08-12T14:51:39Z","vanir_signatures":[{"id":"CVE-2023-49294-36d11e8b","signature_type":"Function","signature_version":"v1","source":"https://github.com/asterisk/asterisk/commit/424be345639d75c6cb7d0bd2da5f0f407dbd0bd5","target":{"file":"main/manager.c","function":"action_getconfig"},"deprecated":false,"digest":{"function_hash":"109588542733539459536459889459393669665","length":1624}},{"deprecated":false,"digest":{"line_hashes":["319262838586030896207615992167318331197","73907467505780613093867596869826946028","190120290691841264546542164833305697156","188451549638797376020687671964111659251","306381406943096252306587444901106669830","281693650920930203770229831242808819948","264207488659524750949476693331686821786","67543373166406810932547016329833398560","97878129604647764779898339292312984812","83119973620778701708573231143751198547","53002410202270671464510830582876964165","287021365016972524448351506910938643808","5465443576409833929852852108939725436","127509060636997878303563635197128916444","293467370214708869510941750821547456454","144039315961212118021668320333867713421","230453289490337290751317884418675546183","208605912000204155817576245907549950226","326430335594905709020873983644130476101"],"threshold":0.9},"id":"CVE-2023-49294-3d2ea2ff","signature_type":"Line","signature_version":"v1","source":"https://github.com/asterisk/asterisk/commit/424be345639d75c6cb7d0bd2da5f0f407dbd0bd5","target":{"file":"main/manager.c"}},{"target":{"file":"main/manager.c","function":"restrictedFile"},"deprecated":false,"digest":{"function_hash":"226786881581905709534996596552064063998","length":226},"id":"CVE-2023-49294-df60a6fc","signature_type":"Function","signature_version":"v1","source":"https://github.com/asterisk/asterisk/commit/424be345639d75c6cb7d0bd2da5f0f407dbd0bd5"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-49294.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N"}]}