Impact
I-Analyzer's media API can be used to read arbitrary files from the system.
Patches
The bug has been resolved in version 5.19.2 of I-Analyzer by introducing path validation and MIME type check on requested files.
Workarounds
It is possible mitigate the scope of the issue by limiting the permissions of the user running I-Analyzer, or running in a constrained environment (e.g. a container).
Impact
I-Analyzer's media API can be used to read arbitrary files from the system.
Patches
The bug has been resolved in version 5.19.2 of I-Analyzer by introducing path validation and MIME type check on requested files.
Workarounds
It is possible mitigate the scope of the issue by limiting the permissions of the user running I-Analyzer, or running in a constrained environment (e.g. a container).