Attackers can access data at arbitrary filesystem paths on the same host as an application using FileMiddleware.
Version 4.29.4
Upgrade to 4.24.4 or later, or disable FileMiddleware.
If you have any questions or comments about this advisory: * Open an issue * Email us at security@vapor.codes
{
"cwe_ids": [
"CWE-22"
],
"github_reviewed": true,
"nvd_published_at": "2020-10-02T19:15:00Z",
"github_reviewed_at": "2023-06-09T19:31:32Z",
"severity": "MODERATE"
}