{"id":"GHSA-qwf7-rv77-fcr3","summary":"Duplicate Advisory: Malicious URL drafting attack against iodines static file server may allow path traversal","details":"### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-85rf-xh54-whp3. This link is maintained to preserve external references.\n\n### Original Description\nPath traversal in the static file service in Iodine less than 0.7.33 allows an unauthenticated, remote attacker to read files outside the public folder via malicious URLs.\n\n","modified":"2026-09-10T03:50:05.190801194Z","published":"2024-01-04T21:30:24Z","withdrawn":"2024-01-05T15:28:54Z","database_specific":{"nvd_published_at":"2024-01-04T21:15:10Z","cwe_ids":["CWE-22"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2024-01-05T15:28:54Z"},"references":[{"type":"WEB","url":"https://github.com/boazsegev/iodine/security/advisories/GHSA-85rf-xh54-whp3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-22050"},{"type":"WEB","url":"https://github.com/boazsegev/iodine/commit/5558233fb7defda706b4f9c87c17759705949889"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-85rf-xh54-whp3"},{"type":"WEB","url":"https://vulncheck.com/advisories/vc-advisory-GHSA-85rf-xh54-whp3"}],"affected":[{"package":{"name":"iodine","ecosystem":"RubyGems","purl":"pkg:gem/iodine"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.0.1","0.0.2","0.0.3","0.0.4","0.1.0","0.1.1","0.1.11","0.1.12","0.1.13","0.1.14","0.1.15","0.1.16","0.1.17","0.1.18","0.1.19","0.1.2","0.1.20","0.1.21","0.1.3","0.1.4","0.1.5","0.1.6","0.1.7","0.1.8","0.1.9","0.2.0","0.2.1","0.2.10","0.2.11","0.2.12","0.2.13","0.2.14","0.2.15","0.2.16","0.2.17","0.2.2","0.2.3","0.2.4","0.2.5","0.2.6","0.2.7","0.2.8","0.2.9","0.3.0","0.3.1","0.3.2","0.3.3","0.3.4","0.3.5","0.3.6","0.4.0","0.4.1","0.4.10","0.4.11","0.4.12","0.4.14","0.4.15","0.4.16","0.4.17","0.4.18","0.4.19","0.4.2","0.4.3","0.4.4","0.4.5","0.4.6","0.4.7","0.4.8","0.5.0","0.5.1","0.5.2","0.6.0","0.6.1","0.6.2","0.6.3","0.6.4","0.6.5","0.7.0","0.7.1","0.7.10","0.7.11","0.7.12","0.7.13","0.7.14","0.7.15","0.7.16","0.7.17","0.7.18","0.7.19","0.7.2","0.7.20","0.7.21","0.7.22","0.7.23","0.7.24","0.7.25","0.7.26","0.7.27","0.7.28","0.7.29","0.7.3","0.7.31","0.7.32","0.7.33","0.7.34","0.7.35","0.7.36","0.7.37","0.7.38","0.7.39","0.7.4","0.7.40","0.7.41","0.7.42","0.7.43","0.7.44","0.7.45","0.7.46","0.7.47","0.7.48","0.7.49","0.7.5","0.7.50","0.7.51","0.7.52","0.7.53","0.7.54","0.7.55","0.7.56","0.7.57","0.7.58","0.7.59","0.7.6","0.7.7","0.7.8","0.7.9"],"database_specific":{"last_known_affected_version_range":"\u003c 0.7.33","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-qwf7-rv77-fcr3/GHSA-qwf7-rv77-fcr3.json"}}],"schema_version":"1.9.0"}