Vulnerability Details CVE-2021-3374
Directory traversal in RStudio Shiny Server before 1.5.16 allows attackers to read the application source code, involving an encoded slash.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.833
EPSS Ranking 99.2%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2021-3374
-
cpe:2.3:a:rstudio:shiny_server:-
-
cpe:2.3:a:rstudio:shiny_server:0.3.0
-
cpe:2.3:a:rstudio:shiny_server:0.3.1
-
cpe:2.3:a:rstudio:shiny_server:0.3.2
-
cpe:2.3:a:rstudio:shiny_server:0.3.3
-
cpe:2.3:a:rstudio:shiny_server:0.3.4
-
cpe:2.3:a:rstudio:shiny_server:0.3.5
-
cpe:2.3:a:rstudio:shiny_server:0.3.6
-
cpe:2.3:a:rstudio:shiny_server:0.4.0
-
cpe:2.3:a:rstudio:shiny_server:0.4.1
-
cpe:2.3:a:rstudio:shiny_server:0.4.2
-
cpe:2.3:a:rstudio:shiny_server:0.5.0
-
cpe:2.3:a:rstudio:shiny_server:1.0.0
-
cpe:2.3:a:rstudio:shiny_server:1.1.0
-
cpe:2.3:a:rstudio:shiny_server:1.2.0
-
cpe:2.3:a:rstudio:shiny_server:1.2.2
-
cpe:2.3:a:rstudio:shiny_server:1.2.3
-
cpe:2.3:a:rstudio:shiny_server:1.3.0
-
cpe:2.3:a:rstudio:shiny_server:1.4.0
-
cpe:2.3:a:rstudio:shiny_server:1.4.1
-
cpe:2.3:a:rstudio:shiny_server:1.4.2
-
cpe:2.3:a:rstudio:shiny_server:1.4.3
-
cpe:2.3:a:rstudio:shiny_server:1.4.4
-
cpe:2.3:a:rstudio:shiny_server:1.4.5
-
cpe:2.3:a:rstudio:shiny_server:1.4.6
-
cpe:2.3:a:rstudio:shiny_server:1.4.7
-
cpe:2.3:a:rstudio:shiny_server:1.5.0
-
cpe:2.3:a:rstudio:shiny_server:1.5.1
-
cpe:2.3:a:rstudio:shiny_server:1.5.10
-
cpe:2.3:a:rstudio:shiny_server:1.5.11
-
cpe:2.3:a:rstudio:shiny_server:1.5.12
-
cpe:2.3:a:rstudio:shiny_server:1.5.13
-
cpe:2.3:a:rstudio:shiny_server:1.5.14
-
cpe:2.3:a:rstudio:shiny_server:1.5.15
-
cpe:2.3:a:rstudio:shiny_server:1.5.2
-
cpe:2.3:a:rstudio:shiny_server:1.5.3
-
cpe:2.3:a:rstudio:shiny_server:1.5.4
-
cpe:2.3:a:rstudio:shiny_server:1.5.5
-
cpe:2.3:a:rstudio:shiny_server:1.5.6
-
cpe:2.3:a:rstudio:shiny_server:1.5.7
-
cpe:2.3:a:rstudio:shiny_server:1.5.8
-
cpe:2.3:a:rstudio:shiny_server:1.5.9