CVE-2020-25623 REJECTED

Erlang/OTP 22.3.x before 22.3.4.6 and 23.x before 23.1 allows Directory Traversal. An attacker can send a crafted HTTP request to read arbitrary files, if httpd in the inets application is used.

EPSS 0.93% · 76.0th percentile

Risk Scores

EPSS Score
0.93%
76.0th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSerlang0, 1:18.0-dfsg-1ubuntu1, 1:18.0-dfsg-1ubuntu2
Ubuntu:20.04:LTSerlang1:22.2.4+dfsg-1, 0, 1:22.0.7+dfsg-1build1
Ubuntu:18.04:LTSerlang1:20.2.1+dfsg-1ubuntu1, 1:20.2.2+dfsg-1ubuntu1, 0

Timeline

References

Open in Interactive Console →