CVE-2021-35397
Estado: ModificadaAlta (7.5)—
A path traversal vulnerability in the static router for Drogon from 1.0.0-beta14 to 1.6.0 could allow an unauthenticated, remote attacker to arbitrarily read files. The vulnerability is due to lack of proper input validation for requested path. An attacker could exploit this vulnerability by sending crafted HTTP request with specific path to read. Successful exploitation could allow the attacker to read files that should be restricted.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 4.01%
- Percentil entre todas las CVEs puntuadas: 90
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-22
Referencias
- https://github.com/an-tao/drogon
- https://github.com/an-tao/drogon/blob/834e3eabdd0441ad2bc80c02e8bbfc3b8312c213/lib/src/StaticFileRouter.cc#L62-L67
- https://github.com/an-tao/drogon/wiki/ENG-02-Installation
- https://github.com/an-tao/drogon/wiki/ENG-03-Quick-Start#Static-Site
- https://github.com/an-tao/drogon
- https://github.com/an-tao/drogon/blob/834e3eabdd0441ad2bc80c02e8bbfc3b8312c213/lib/src/StaticFileRouter.cc#L62-L67
- https://github.com/an-tao/drogon/wiki/ENG-02-Installation
- https://github.com/an-tao/drogon/wiki/ENG-03-Quick-Start#Static-Site
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-35397",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2021-08-04T11:15:08.003",
"references": [
{
"url": "https://github.com/an-tao/drogon",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/an-tao/drogon/blob/834e3eabdd0441ad2bc80c02e8bbfc3b8312c213/lib/src/StaticFileRouter.cc#L62-L67",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/an-tao/drogon/wiki/ENG-02-Installation",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/an-tao/drogon/wiki/ENG-03-Quick-Start#Static-Site",
"tags": [
"Third Party Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/an-tao/drogon",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/an-tao/drogon/blob/834e3eabdd0441ad2bc80c02e8bbfc3b8312c213/lib/src/StaticFileRouter.cc#L62-L67",
"tags": [
"Exploit",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/an-tao/drogon/wiki/ENG-02-Installation",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/an-tao/drogon/wiki/ENG-03-Quick-Start#Static-Site",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A path traversal vulnerability in the static router for Drogon from 1.0.0-beta14 to 1.6.0 could allow an unauthenticated, remote attacker to arbitrarily read files. The vulnerability is due to lack of proper input validation for requested path. An attacker could exploit this vulnerability by sending crafted HTTP request with specific path to read. Successful exploitation could allow the attacker to read files that should be restricted."
},
{
"lang": "es",
"value": "Una vulnerabilidad de salto de ruta en el enrutador estático para Drogon desde versión 1.0.0-beta14 hasta 1.6.0, podría permitir a un atacante remoto no autenticado leer archivos de forma arbitraria. La vulnerabilidad es debido a una falta de comprobación de entrada apropiada para la ruta de acceso solicitada. Un atacante podría explotar esta vulnerabilidad mediante el envío de una petición HTTP diseñada con una ruta específica para leer. Una explotación con éxito podría permitir al atacante leer archivos que deberían estar restringidos"
}
],
"lastModified": "2026-06-17T03:57:29.560",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:drogon:drogon:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2D1827E9-B961-46A5-8C75-962996DBA831",
"versionEndIncluding": "1.6.0",
"versionStartIncluding": "1.1.0"
},
{
"criteria": "cpe:2.3:a:drogon:drogon:1.0.0:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3FE62923-CE5D-4200-9F1D-BFC95E695D6A"
},
{
"criteria": "cpe:2.3:a:drogon:drogon:1.0.0:beta14:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0F1B3195-9E7C-4015-B21B-888417158985"
},
{
"criteria": "cpe:2.3:a:drogon:drogon:1.0.0:beta15:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "362C466E-8B87-477F-A454-4AB1F4FCF6C5"
},
{
"criteria": "cpe:2.3:a:drogon:drogon:1.0.0:beta16:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8EF8B059-B85F-4EEF-8CFE-E441E4563577"
},
{
"criteria": "cpe:2.3:a:drogon:drogon:1.0.0:beta17:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EDBF5CD1-A4AE-461F-B0ED-88ACAA1D92A0"
},
{
"criteria": "cpe:2.3:a:drogon:drogon:1.0.0:beta18:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "26DC09CF-AFA1-4AE8-9267-95A5D01E88DD"
},
{
"criteria": "cpe:2.3:a:drogon:drogon:1.0.0:beta19:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "15346F7B-A84E-4E92-98F2-F906737FA353"
},
{
"criteria": "cpe:2.3:a:drogon:drogon:1.0.0:beta20:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9FFD1D23-0025-4177-AA30-E6213D0B042D"
},
{
"criteria": "cpe:2.3:a:drogon:drogon:1.0.0:beta21:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CB90905F-016A-42D0-B94A-30D3AB7A051F"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}