← Back

CVE-2020-36559

nvd nist
Published: Dec 27, 2022Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

Due to improper sanitization of user input, HTTPEngine.Handle allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read.

Affected (1)

Products: Aahframework: Aah
1 product
Aah
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 0.12.4

References (8)

Source: security@golang.org
PatchThird Party Advisory
Source: security@golang.org
Issue TrackingThird Party Advisory
Source: security@golang.org
Third Party Advisory
Source: security@golang.org
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.