VDB
CVE-2020-36565
CVE-2020-36565
PUBLISHED
Due to improper sanitization of user input on Windows, the static file handler allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read.
EPSS 0.30% · 53.1th percentile
Risk Scores
EPSS Score
0.30%
53.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:22.04:LTS | golang-github-labstack-echo | 0, 4.2.1-2 |
| Ubuntu:25.10 | golang-github-labstack-echo | 0, 4.12.0-1 |
| Ubuntu:24.04:LTS | golang-github-labstack-echo | 0, 4.11.1-2 |
Exploit Intelligence
Timeline
- Apr 14, 2021 CVE Published
- Dec 8, 2022 EPSS Score
- Dec 28, 2022 EPSS Score
- Jan 19, 2023 EPSS Score
- Feb 23, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 13, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 6, 2023 EPSS Score
- Aug 17, 2023 EPSS Score
- Sep 28, 2023 EPSS Score
- Nov 9, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2020-36565 third-party-advisory
- https://pkg.go.dev/vuln/GO-2021-0051 third-party-advisory
- https://github.com/labstack/echo/pull/1718 third-party-advisory
- https://github.com/labstack/echo/commit/4422e3b66b9fd498ed1ae1d0242d660d0ed3faaa third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2020-36565 third-party-advisory