The File Download API in Wipro Holmes Orchestrator 20.4.1...
High severity
Unreviewed
Published
Nov 23, 2021
to the GitHub Advisory Database
•
Updated Feb 28, 2024
Description
Published by the National Vulnerability Database
Nov 22, 2021
Published to the GitHub Advisory Database
Nov 23, 2021
Last updated
Feb 28, 2024
The File Download API in Wipro Holmes Orchestrator 20.4.1 (20.4.1_02_11_2020) allows remote attackers to read arbitrary files via absolute path traversal in the SearchString JSON field in /home/download POST data.
References