Vapor · Vapor · CVE-2020-15230
**Name of the Vulnerable Software and Affected Versions**
Vapor versions prior to 4.29.4
**Description**
Attackers can access data at arbitrary filesystem paths on the same host as an application using `FileMiddleware`. This issue affects applications that use `FileMiddleware`.
**Recommendations**
For versions prior to 4.29.4, upgrade to version 4.29.4 or later.
As a temporary workaround, consider disabling `FileMiddleware` until a patch is available.