RULE(RULE ID:333507)

Rule General Information
Release Date: 2021-04-28
Rule Name: Ffay Lanproxy Directory Traversal Vulnerability (CVE-2021-3019)
Severity:
CVE ID:
Rule Protection Details
Description: ffay lanproxy 0.1 allows Directory Traversal to read /../conf/config.properties to obtain credentials for a connection to the intranet.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows, Linux, Others
Reference: https://github.com/ffay/lanproxy/commits/master
https://github.com/maybe-why-not/lanproxy/issues/1
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://github.com/ffay/lanproxy/commits/master