CVE-2019-12479
Last modified
CVE-2019-12479 is a vulnerability of currently unknown severity. An issue was discovered in 20|20 Storage 2.11.0. A Path Traversal vulnerability in the TwentyTwenty.Storage library in the LocalStorageProvider allows creating and reading files outside of the specified basepath. EPSS estimates a 2.01% chance of exploitation in the next 30 days.
Description
An issue was discovered in 20|20 Storage 2.11.0. A Path Traversal vulnerability in the TwentyTwenty.Storage library in the LocalStorageProvider allows creating and reading files outside of the specified basepath. If the application using this library does not sanitize user-supplied filenames, then this issue may be exploited to read or write arbitrary files. This affects LocalStorageProvider.cs.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Twentytwenty.Storage Project | Twentytwenty.Storage | 2.11.0 |
References
- https://security401.com/twentytwenty-storage-path-traversal/Exploit, Third Party Advisory
- https://security401.com/twentytwenty-storage-path-traversal/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-12479?
How severe is CVE-2019-12479?
How do I fix CVE-2019-12479?
Are you affected by CVE-2019-12479?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
