VDB
CVE-2020-36565
CVE-2020-36565
PUBLISHED
CVSS 5.300000190734863 MEDIUM
Due to improper sanitization of user input on Windows, the static file handler allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read.
EPSS 1.32% · 68.6th percentile
Risk Scores
CVSS 3.1
5.300000190734863
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
1.32%
68.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:22.04:LTS | golang-github-labstack-echo | 0, 4.2.1-2 |
| Ubuntu:25.10 | golang-github-labstack-echo | 0, 4.12.0-1 |
| Ubuntu:24.04:LTS | golang-github-labstack-echo | 0, 4.11.1-2 |
Timeline
- Apr 14, 2021 CVE Published
- Dec 8, 2022 EPSS Score
- Dec 28, 2022 EPSS Score
- Jan 19, 2023 EPSS Score
- Mar 3, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 14, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Jul 7, 2023 EPSS Score
- Aug 19, 2023 EPSS Score
- Nov 11, 2023 EPSS Score
- Dec 23, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2020-36565 third-party-advisory
- https://pkg.go.dev/vuln/GO-2021-0051 third-party-advisory
- https://github.com/labstack/echo/pull/1718 third-party-advisory
- https://github.com/labstack/echo/commit/4422e3b66b9fd498ed1ae1d0242d660d0ed3faaa third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2020-36565 third-party-advisory