From e1adf856e4cbec5b02480a22900441e6589d9efd Mon Sep 17 00:00:00 2001 From: GitHub Action Date: Thu, 14 Oct 2021 10:52:45 +0000 Subject: [PATCH] Auto Generated CVE annotations [Thu Oct 14 10:52:45 UTC 2021] :robot: --- cves/2021/CVE-2021-40978.yaml | 1 + 1 file changed, 1 insertion(+) diff --git a/cves/2021/CVE-2021-40978.yaml b/cves/2021/CVE-2021-40978.yaml index 47dae4ec2f..2273074039 100644 --- a/cves/2021/CVE-2021-40978.yaml +++ b/cves/2021/CVE-2021-40978.yaml @@ -8,6 +8,7 @@ info: - https://github.com/nisdn/CVE-2021-40978 - https://nvd.nist.gov/vuln/detail/CVE-2021-40978 tags: cve,cve2021,mkdocs,lfi + description: "** DISPUTED ** The mkdocs 1.2.2 built-in dev-server allows directory traversal using the port 8000, enabling remote exploitation to obtain :sensitive information. NOTE: the vendor has disputed this as described in https://github.com/mkdocs/mkdocs/issues/2601.] and https://github.com/nisdn/CVE-2021-40978/issues/1." requests: - method: GET