ServiceStack.Text is vulnerable to External Control of File Name or Path
61
Medium Risk
Affected versions of this package are vulnerable to external control of file name or path through the url parameter in the GetErrorResponse method. An attacker can exploit this by supplying a file:// URI, potentially causing the application to relay NTLM credentials in the context of the current user. However, the maintainers note that the security impact is limited, as the same behavior exists in the underlying .NET WebRequest.Create(url) method that this package wraps, and no additional risk is introduced by the wrapper itself.
You are affected if you are using a version that falls within the vulnerable range.
ServiceStack.Text is vulnerable to External Control of File Name or Path in versions 6.0.0 - 8.5.2.
Upgrade the ServiceStack.Text library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant