PT-2020-14204 · Intranda · Goobi Viewer Core
Janvonde
·
Published
2020-07-22
·
Updated
2020-07-24
·
CVE-2020-15124
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Goobi Viewer Core versions prior to 4.8.3
Description
A path traversal issue allows remote attackers to access files on the server via the application, potentially leading to the disclosure of sensitive information. This is limited to files accessible to the application server user.
Recommendations
For versions prior to 4.8.3, update to version 4.8.3 to resolve the issue.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Goobi Viewer Core