{"id":"GHSA-qg5v-jw6f-rpfj","summary":"SabreDAV Directory Traversal vulnerability","details":"The HTML\\Browser plugin in SabreDAV before 1.6.9, 1.7.x before 1.7.7, and 1.8.x before 1.8.5, as used in ownCloud, when running on Windows, does not properly check path separators in the base path, which allows remote attackers to read arbitrary files via a `\\` (backslash) character.","aliases":["CVE-2013-1939"],"modified":"2024-12-04T05:29:58.274167Z","published":"2022-05-14T01:52:20Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-07-07T15:45:57Z","nvd_published_at":"2014-03-14T16:55:00Z","cwe_ids":["CWE-20","CWE-22"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-1939"},{"type":"WEB","url":"https://github.com/FriendsOfPHP/security-advisories/blob/master/sabre/dav/CVE-2013-1939.yaml"},{"type":"PACKAGE","url":"https://github.com/sabre-io/dav"},{"type":"WEB","url":"https://groups.google.com/forum/?fromgroups=#!topic/sabredav-discuss/ehOUu7wTSGQ"},{"type":"WEB","url":"https://groups.google.com/forum/?fromgroups=#%21topic/sabredav-discuss/ehOUu7wTSGQ"},{"type":"WEB","url":"http://owncloud.org/about/security/advisories/oC-SA-2013-016"}],"affected":[{"package":{"name":"sabre/dav","ecosystem":"Packagist","purl":"pkg:composer/sabre/dav"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.7.0"},{"fixed":"1.7.7"}]}],"versions":["1.7.0","1.7.1","1.7.2","1.7.3","1.7.4","1.7.5","1.7.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qg5v-jw6f-rpfj/GHSA-qg5v-jw6f-rpfj.json"}},{"package":{"name":"sabre/dav","ecosystem":"Packagist","purl":"pkg:composer/sabre/dav"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.8.0"},{"fixed":"1.8.5"}]}],"versions":["1.8.0","1.8.1","1.8.2","1.8.3","1.8.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qg5v-jw6f-rpfj/GHSA-qg5v-jw6f-rpfj.json"}},{"package":{"name":"sabre/dav","ecosystem":"Packagist","purl":"pkg:composer/sabre/dav"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.6.0"},{"fixed":"1.6.9"}]}],"versions":["1.6.0","1.6.1","1.6.2","1.6.3","1.6.4","1.6.5","1.6.6","1.6.7","1.6.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qg5v-jw6f-rpfj/GHSA-qg5v-jw6f-rpfj.json"}}],"schema_version":"1.9.0"}