Vulnerability Details CVE-2021-3374
Directory traversal in RStudio Shiny Server before 1.5.16 allows attackers to read the application source code, involving an encoded slash.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.746
EPSS Ranking 98.8%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2021-3374
-
cpe:2.3:a:rstudio:shiny_server:-
-
cpe:2.3:a:rstudio:shiny_server:0.3.0
-
cpe:2.3:a:rstudio:shiny_server:0.3.1
-
cpe:2.3:a:rstudio:shiny_server:0.3.2
-
cpe:2.3:a:rstudio:shiny_server:0.3.3
-
cpe:2.3:a:rstudio:shiny_server:0.3.4
-
cpe:2.3:a:rstudio:shiny_server:0.3.5
-
cpe:2.3:a:rstudio:shiny_server:0.3.6
-
cpe:2.3:a:rstudio:shiny_server:0.4.0
-
cpe:2.3:a:rstudio:shiny_server:0.4.1
-
cpe:2.3:a:rstudio:shiny_server:0.4.2
-
cpe:2.3:a:rstudio:shiny_server:0.5.0
-
cpe:2.3:a:rstudio:shiny_server:1.0.0
-
cpe:2.3:a:rstudio:shiny_server:1.1.0
-
cpe:2.3:a:rstudio:shiny_server:1.2.0
-
cpe:2.3:a:rstudio:shiny_server:1.2.2
-
cpe:2.3:a:rstudio:shiny_server:1.2.3
-
cpe:2.3:a:rstudio:shiny_server:1.3.0
-
cpe:2.3:a:rstudio:shiny_server:1.4.0
-
cpe:2.3:a:rstudio:shiny_server:1.4.1
-
cpe:2.3:a:rstudio:shiny_server:1.4.2
-
cpe:2.3:a:rstudio:shiny_server:1.4.3
-
cpe:2.3:a:rstudio:shiny_server:1.4.4
-
cpe:2.3:a:rstudio:shiny_server:1.4.5
-
cpe:2.3:a:rstudio:shiny_server:1.4.6
-
cpe:2.3:a:rstudio:shiny_server:1.4.7
-
cpe:2.3:a:rstudio:shiny_server:1.5.0
-
cpe:2.3:a:rstudio:shiny_server:1.5.1
-
cpe:2.3:a:rstudio:shiny_server:1.5.10
-
cpe:2.3:a:rstudio:shiny_server:1.5.11
-
cpe:2.3:a:rstudio:shiny_server:1.5.12
-
cpe:2.3:a:rstudio:shiny_server:1.5.13
-
cpe:2.3:a:rstudio:shiny_server:1.5.14
-
cpe:2.3:a:rstudio:shiny_server:1.5.15
-
cpe:2.3:a:rstudio:shiny_server:1.5.2
-
cpe:2.3:a:rstudio:shiny_server:1.5.3
-
cpe:2.3:a:rstudio:shiny_server:1.5.4
-
cpe:2.3:a:rstudio:shiny_server:1.5.5
-
cpe:2.3:a:rstudio:shiny_server:1.5.6
-
cpe:2.3:a:rstudio:shiny_server:1.5.7
-
cpe:2.3:a:rstudio:shiny_server:1.5.8
-
cpe:2.3:a:rstudio:shiny_server:1.5.9