CVE-2022-4773

Source
https://cve.org/CVERecord?id=CVE-2022-4773
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-4773.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-4773
Published
2022-12-27T23:05:37.534Z
Modified
2026-07-22T02:08:50.654741Z
Severity
  • 2.5 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
cloudsync LocalFilesystemConnector.java getItem path traversal
Details

** UNSUPPORTED WHEN ASSIGNED ** A vulnerability classified as problematic was found in cloudsync. Affected by this vulnerability is the function getItem of the file src/main/java/cloudsync/connector/LocalFilesystemConnector.java. The manipulation leads to path traversal. It is possible to launch the attack on the local host. The name of the patch is 3ad796833398af257c28e0ebeade68518e0e612a. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216919. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.

Database specific
{
    "cna_assigner": "VulDB",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/4xxx/CVE-2022-4773.json",
    "cwe_ids": [
        "CWE-22"
    ]
}
References

Affected packages

Git / github.com/holgerhees/cloudsync

Affected ranges

Type
GIT
Repo
https://github.com/holgerhees/cloudsync
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "source": "REFERENCES"
}

Affected versions

v1.*
v1.0-beta1
v1.0-beta10
v1.0-beta11
v1.0-beta12
v1.0-beta14
v1.0-beta2
v1.0-beta3
v1.0-beta4
v1.0-beta5
v1.0-beta6
v1.0-beta7
v1.0-beta8
v1.0-beta9

Database specific

vanir_signatures
[
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "length": 4064.0,
            "function_hash": "109783577688533687957683343273447491471"
        },
        "id": "CVE-2022-4773-40ced546",
        "signature_type": "Function",
        "source": "https://github.com/holgerhees/cloudsync/commit/3ad796833398af257c28e0ebeade68518e0e612a",
        "target": {
            "function": "getItem",
            "file": "src/main/java/cloudsync/connector/LocalFilesystemConnector.java"
        }
    },
    {
        "signature_version": "v1",
        "deprecated": false,
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "89420516857254812841816402803818866145",
                "92420760527762796989155655024272266546",
                "242475902173834287261730207130887936764",
                "250370438620134956514027567194699495224"
            ]
        },
        "id": "CVE-2022-4773-a8313621",
        "signature_type": "Line",
        "source": "https://github.com/holgerhees/cloudsync/commit/3ad796833398af257c28e0ebeade68518e0e612a",
        "target": {
            "file": "src/main/java/cloudsync/connector/LocalFilesystemConnector.java"
        }
    }
]
vanir_signatures_modified
"2026-07-22T02:08:50Z"
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-4773.json"