PT-2020-14296 · Vapor · Vapor

Lmcd

+1

·

Published

2020-10-02

·

Updated

2023-06-09

·

CVE-2020-15230

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Vapor versions prior to 4.29.4
Description Attackers can access data at arbitrary filesystem paths on the same host as an application using FileMiddleware. This issue affects applications that use FileMiddleware.
Recommendations For versions prior to 4.29.4, upgrade to version 4.29.4 or later. As a temporary workaround, consider disabling FileMiddleware until a patch is available.

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2020-15230
GHSA-VCVG-XGR8-P5GQ

Affected Products

Vapor