CVE-2020-21526: Path Traversal
Published Sep 30, 2020
·Updated
An Arbitrary file writing vulnerability in halo v1.1.3. In an interface to write files in the background, a directory traversal check is performed on the input path parameter, but the startsWith function can be used to bypass it.
Affected Software
1 affected component
Halo Halo=1.1.3
Event History
Sep 30, 2020
CVE Published
via MITRE·02:43 PM
Data Sourced
via MITRE·02:43 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-21526?
The severity of CVE-2020-21526 is critical with a CVSS score of 9.8.
2
How does CVE-2020-21526 affect Halo version 1.1.3?
CVE-2020-21526 affects Halo version 1.1.3.
3
What is the vulnerability in CVE-2020-21526?
CVE-2020-21526 is an Arbitrary file writing vulnerability in Halo v1.1.3.
4
How can the directory traversal check be bypassed in CVE-2020-21526?
The startsWith function can be used to bypass the directory traversal check in CVE-2020-21526.
5
Is there a fix available for CVE-2020-21526?
At the time of writing, there is no specific fix available for CVE-2020-21526. It is recommended to update to a patched version or apply any available security patches.