Arbitrary Filesystem Path Access Vulnerability in Vapor Web Framework

Arbitrary Filesystem Path Access Vulnerability in Vapor Web Framework

CVE-2020-15230 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Vapor is a web framework for Swift. In Vapor before version 4.29.4, Attackers can access data at arbitrary filesystem paths on the same host as an application. Only applications using FileMiddleware are affected. This is fixed in version 4.29.4.

Learn more about our Web App Pen Testing.