Description
An issue was discovered in 20|20 Storage 2.11.0. A Path Traversal vulnerability in the TwentyTwenty.Storage library in the LocalStorageProvider allows creating and reading files outside of the specified basepath. If the application using this library does not sanitize user-supplied filenames, then this issue may be exploited to read or write arbitrary files. This affects LocalStorageProvider.cs.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-4075 | An issue was discovered in 20|20 Storage 2.11.0. A Path Traversal vulnerability in the TwentyTwenty.Storage library in the LocalStorageProvider allows creating and reading files outside of the specified basepath. If the application using this library does not sanitize user-supplied filenames, then this issue may be exploited to read or write arbitrary files. This affects LocalStorageProvider.cs. |
References
| Link | Providers |
|---|---|
| https://security401.com/twentytwenty-storage-path-traversal/ |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T23:24:37.919Z
Reserved: 2019-05-30T00:00:00.000Z
Link: CVE-2019-12479
No data.
Status : Modified
Published: 2019-08-13T21:15:11.347
Modified: 2024-11-21T04:22:56.580
Link: CVE-2019-12479
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD