Back to Vulnerability Directory
HIGHFixed upstream
CVE-2020-25623
Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Directory Traversal.
Technology
Erlang/OTP
CVSS Score
7.5 / 10.0
Affected Versions
>=22.3.0 <22.3.4.6; >=23.0.0 <23.1
Upstream Fix
See upstream advisory
Published
October 2, 2020
OSSeva Coverage
Fixed upstream
Description
Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Directory Traversal. An attacker can send a crafted HTTP request to read arbitrary files, if httpd in the inets application is used.
Is your Erlang/OTP deployment affected?
If you're running >=22.3.0 <22.3.4.6; >=23.0.0 <23.1, you need this patch. Book a discovery call to get covered.