Back to Vulnerability Directory
HIGHFixed upstream

CVE-2020-25623

Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Directory Traversal.

Technology

Erlang/OTP

CVSS Score

7.5 / 10.0

Affected Versions

>=22.3.0 <22.3.4.6; >=23.0.0 <23.1

Upstream Fix

See upstream advisory

Published

October 2, 2020

OSSeva Coverage

Fixed upstream

Description

Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Directory Traversal. An attacker can send a crafted HTTP request to read arbitrary files, if httpd in the inets application is used.

Is your Erlang/OTP deployment affected?

If you're running >=22.3.0 <22.3.4.6; >=23.0.0 <23.1, you need this patch. Book a discovery call to get covered.