CVE-2020-29441: Malicious File Upload
An issue was discovered in the Upload Widget in OutSystems Platform 10 before 10.0.1019.0. An unauthenticated attacker can upload arbitrary files. In some cases, this attack may consume the available database space (Denial of Service), corrupt legitimate data if files are being processed asynchronously, or deny access to legitimate uploaded files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-29441?
The severity of CVE-2020-29441 is high with a CVSS base score of 6.5.
How does CVE-2020-29441 affect OutSystems Platform?
CVE-2020-29441 allows an unauthenticated attacker to upload arbitrary files and may consume the available database space (Denial of Service) or corrupt legitimate data if files are being processed asynchronously.
What version of OutSystems Platform is affected by CVE-2020-29441?
OutSystems Platform 10 before version 10.0.1019.0 is affected by CVE-2020-29441.
Is there a fix available for CVE-2020-29441?
Yes, upgrading to OutSystems Platform version 10.0.1019.0 or later will fix CVE-2020-29441.
Where can I find more information about CVE-2020-29441?
More information about CVE-2020-29441 can be found at the following URL: https://success.outsystems.com/Support/Security/Vulnerabilities/Vulnerability_RPD-4310