CVE-2023-36654

Publication date

2023-12-12 00:00:00

Family

mitre

State

PUBLISHED

Description

Directory traversal in the log-download REST API endpoint in ProLion CryptoSpike 3.0.15P2 allows remote authenticated attackers to download host server SSH private keys (associated with a Linux root user) by injecting paths inside REST API endpoint parameters.