Vapor is a web framework for Swift. In Vapor before version 4.29.4, Attackers can access data at arbitrary filesystem paths on the same host as an application. Only applications using FileMiddleware are affected. This is fixed in version 4.29.4.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1889 | Vapor is a web framework for Swift. In Vapor before version 4.29.4, Attackers can access data at arbitrary filesystem paths on the same host as an application. Only applications using FileMiddleware are affected. This is fixed in version 4.29.4. |
Github GHSA |
GHSA-vcvg-xgr8-p5gq | Arbitrary file read using percent-encoded relative paths in FileMiddleware |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-04T13:08:22.827Z
Reserved: 2020-06-25T00:00:00
Link: CVE-2020-15230
No data.
Status : Modified
Published: 2020-10-02T19:15:12.963
Modified: 2024-11-21T05:05:08.610
Link: CVE-2020-15230
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA