CVE-2022-36007 is a partial path traversal vulnerability affecting Venice, a Clojure-inspired Lisp dialect, in versions prior to 1.10.18. Specifically, the load-file and load-resource functions can be tricked into loading files outside configured load paths when provided with absolute paths that share a common prefix with an allowed load path. The vulnerability has a CVSS score of 3.3 (LOW), indicating a low severity. It requires local access and low privileges (AV:L/PR:L), with low attack complexity (AC:L). The potential impact is limited to confidentiality (C:L), as it allows an attacker to read unauthorized files, but does not impact integrity or availability. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, suggesting low public awareness and attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.10.17CPE matchmatch criteria | cpe:2.3:a:venice_project:venice:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.