The multifilesystem storage backend in Radicale before 1.1 allows remote attackers to read or write to arbitrary files via a crafted component name.
CVSS Details
- CVSS 3.1 Base Score: 10
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade radicale | Mar 14, 2016 | Jan 30, 2016 |
| Freebsd | — | Upgrade py33-radicaleUpgrade py27-radicaleUpgrade py32-radicaleUpgrade py34-radicale | Dec 10, 2025 | Jan 29, 2016 |
| Ubuntu | — | Upgrade radicale | Nov 19, 2024 | Feb 3, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub