CVE-2020-15230
Summary
| CVE | CVE-2020-15230 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-10-02 19:15:00 UTC |
| Updated | 2022-06-07 18:11:00 UTC |
| Description | Vapor is a web framework for Swift. In Vapor before version 4.29.4, Attackers can access data at arbitrary filesystem paths on the same host as an application. Only applications using FileMiddleware are affected. This is fixed in version 4.29.4. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Vapor Project | Vapor | All | All | All | All |
| Application | Vapor Project | Vapor | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fix relative percent decoding in FileMiddleware by tanner0101 · Pull Request #2500 · vapor/vapor · GitHub | MISC | github.com | Third Party Advisory |
| fix relative percent decoding in file middleware (#2500) · vapor/vapor@cf1651f · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Arbitrary file read using percent-encoded relative paths in FileMiddleware · Advisory · vapor/vapor · GitHub | CONFIRM | github.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.