CVE-2020-21522: Path Traversal
An issue was discovered in halo V1.1.3. A Zip Slip Directory Traversal Vulnerability in the backend,the attacker can overwrite some files, such as ftl files, .bashrc files in the user directory, and finally get the permissions of the operating system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-21522?
CVE-2020-21522 is rated as a high severity vulnerability due to the potential for file overwriting and privilege escalation.
How do I fix CVE-2020-21522?
To fix CVE-2020-21522, upgrade to a patched version of Halo that addresses the Zip Slip Directory Traversal Vulnerability.
What types of files can be overwritten due to CVE-2020-21522?
Due to CVE-2020-21522, attackers can overwrite files such as ftl files and .bashrc files in the user directory.
Who is affected by CVE-2020-21522?
Users of Halo version 1.1.3 are affected by CVE-2020-21522, particularly those with access to the backend.
What can attackers do by exploiting CVE-2020-21522?
By exploiting CVE-2020-21522, attackers can overwrite sensitive files and potentially gain operating system permissions.