CVE-2020-21525: Path Traversal
Published Sep 30, 2020
·Updated
Halo V1.1.3 is affected by: Arbitrary File reading. In an interface that reads files in halo v1.1.3, a directory traversal check is performed on the input path parameter, but the startsWith function can be used to bypass it.
Affected Software
1 affected component
Halo Halo=1.1.3
Event History
Sep 30, 2020
CVE Published
via MITRE·02:38 PM
Data Sourced
via MITRE·02:38 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-21525?
CVE-2020-21525 has a medium severity rating due to its potential to allow arbitrary file reading.
2
How do I fix CVE-2020-21525?
To fix CVE-2020-21525, update Halo to a version that includes the fix for the arbitrary file reading vulnerability.
3
What software is affected by CVE-2020-21525?
CVE-2020-21525 specifically affects Halo version 1.1.3.
4
What type of vulnerability is CVE-2020-21525?
CVE-2020-21525 is categorized as an arbitrary file reading vulnerability.
5
Can CVE-2020-21525 be exploited remotely?
Yes, CVE-2020-21525 can potentially be exploited remotely through specially crafted input that bypasses directory traversal checks.