PT-2020-14204 · Intranda · Goobi Viewer Core

Janvonde

·

Published

2020-07-22

·

Updated

2020-07-24

·

CVE-2020-15124

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Goobi Viewer Core versions prior to 4.8.3
Description A path traversal issue allows remote attackers to access files on the server via the application, potentially leading to the disclosure of sensitive information. This is limited to files accessible to the application server user.
Recommendations For versions prior to 4.8.3, update to version 4.8.3 to resolve the issue.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15124
GHSA-7GWQ-XQW3-CR63

Affected Products

Goobi Viewer Core