PT-2020-17164 · Outsystems · Outsystems Platform

Published

2020-11-30

·

Updated

2020-12-04

·

CVE-2020-29441

CVSS v3.1

7.2

High

VectorAC:L/AV:N/A:L/C:N/I:L/PR:N/S:C/UI:N
Name of the Vulnerable Software and Affected Versions OutSystems Platform 10 versions prior to 10.0.1019.0
Description An issue in the Upload Widget allows an unauthenticated attacker to upload arbitrary files. This can lead to a Denial of Service by consuming available database space, corrupt legitimate data if files are processed asynchronously, or deny access to legitimate uploaded files.
Recommendations For OutSystems Platform 10 versions prior to 10.0.1019.0, update to version 10.0.1019.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the Upload Widget to prevent arbitrary file uploads until a patch is applied.

Fix

DoS

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-29441

Affected Products

Outsystems Platform