GHSA-vcvg-xgr8-p5gq

Suggest an improvement
Source
https://github.com/advisories/GHSA-vcvg-xgr8-p5gq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/06/GHSA-vcvg-xgr8-p5gq/GHSA-vcvg-xgr8-p5gq.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-vcvg-xgr8-p5gq
Aliases
Published
2023-06-09T19:31:32Z
Modified
2026-07-08T06:00:43Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Arbitrary file read using percent-encoded relative paths in FileMiddleware
Details

Impact

Attackers can access data at arbitrary filesystem paths on the same host as an application using FileMiddleware.

Patches

Version 4.29.4

Workarounds

Upgrade to 4.24.4 or later, or disable FileMiddleware.

References

For more information

If you have any questions or comments about this advisory:

Database specific
{
    "cwe_ids":  [
        "CWE-22"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2023-06-09T19:31:32Z",
    "nvd_published_at":  "2020-10-02T19:15:00Z",
    "severity":  "MODERATE"
}
References

Affected packages

SwiftURL / github.com/vapor/vapor

Package

Name
github.com/vapor/vapor
Purl
pkg:swift/github.com/vapor/vapor

Affected ranges

Type
SEMVER
Events
Introduced
4.0.0-rc.2.5
Fixed
4.29.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/06/GHSA-vcvg-xgr8-p5gq/GHSA-vcvg-xgr8-p5gq.json"