HIGH

CVE-2021-40978

CVSS v3

7.5

HIGH

EPSS Score

84.8%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The mkdocs 1.2.2 built-in dev-server allows directory traversal using the port 8000, enabling remote exploitation to obtain :sensitive information. NOTE: the vendor has disputed this as described in https://github.com/mkdocs/mkdocs/issues/2601.] and https://github.com/nisdn/CVE-2021-40978/issues/1

Technical details

Published
10/7/2021

Frequently asked questions

What is CVE-2021-40978?

The mkdocs 1.2.2 built-in dev-server allows directory traversal using the port 8000, enabling remote exploitation to obtain :sensitive information. NOTE: the vendor has disputed this as described in https://github.com/mkdocs/mkdocs/issues/2601.] and https://github.com/nisdn/CVE-2021-40978/issues/1

Is CVE-2021-40978 actively exploited?

Active exploitation of CVE-2021-40978 has not been confirmed. The EPSS score is 84.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-40978?

CVE-2021-40978 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2021-40978 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.