CVE-2020-15230 Information
Feb 14, 2021
cve
Description
Vapor is a web framework for Swift. In Vapor before version 4.29.4 Attackers can access data at arbitrary filesystem paths on the same host as an application. Only applications using FileMiddleware are affected. This is fixed in version 4.29.4.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Reference
https://github.com/vapor/vapor/commit/cf1651f7ff76515593f4d8ca6e6e15d2247fe255 https://github.com/vapor/vapor/pull/2500 https://github.com/vapor/vapor/security/advisories/GHSA-vcvg-xgr8-p5gq
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
NONE
Base Score
NONE
Base Severity
6.5
Share on: