Arbitrary file read using percent-encoded relative paths in FileMiddleware
Package
Affected versions
>= 4.0.0-rc.2.5, < 4.29.4
Patched versions
4.29.4
Description
Published by the National Vulnerability Database
Oct 2, 2020
Published to the GitHub Advisory Database
Jun 9, 2023
Reviewed
Jun 9, 2023
Last updated
Jun 19, 2023
Impact
Attackers can access data at arbitrary filesystem paths on the same host as an application using
FileMiddleware
.Patches
Version 4.29.4
Workarounds
Upgrade to 4.24.4 or later, or disable
FileMiddleware
.References
For more information
If you have any questions or comments about this advisory:
References