Due to improper sanitization of user input, HTTPEngine.Handle allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: Go

Published: 2022-12-27T21:13:19.169Z

Updated: 2024-08-04T17:30:08.397Z

Reserved: 2022-07-29T16:03:51.232Z

Link: CVE-2020-36559

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-12-27T22:15:11.500

Modified: 2024-11-21T05:29:50.100

Link: CVE-2020-36559

cve-icon Redhat

No data.