An issue was discovered in Sangoma Asterisk through 16.28, 17 and 18 through 18.14, 19 through 19.6, and certified through 18.9-cert1. GetConfig, via Asterisk Manager Interface, allows a connected application to access files outside of the asterisk configuration directory, aka Directory Traversal.
{
"versions": [
{
"introduced": "16.0.0"
},
{
"fixed": "16.29.1"
},
{
"introduced": "17.0.0"
},
{
"fixed": "18.15.1"
},
{
"introduced": "19.0.0"
},
{
"fixed": "19.7.1"
},
{
"introduced": "0"
},
{
"last_affected": "20.0.0"
},
{
"introduced": "0"
},
{
"fixed": "18.9"
},
{
"introduced": "0"
},
{
"last_affected": "18.9-cert1"
}
]
}