CVE-2019-12479
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An issue was discovered in 20|20 Storage 2.11.0. A Path Traversal vulnerability in the TwentyTwenty.Storage library in the LocalStorageProvider allows creating and reading files outside of the specified basepath. If the application using this library does not sanitize user-supplied filenames, then this issue may be exploited to read or write arbitrary files. This affects LocalStorageProvider.cs.
Se descubriĆ³ un problema en 20|20 Storage 2.11.0. Una vulnerabilidad de Ruta transversal en la biblioteca TwentyTwenty.Storage en LocalStorageProvider permite crear y leer archivos fuera de la ruta base especificada. Si la aplicaciĆ³n que usa esta biblioteca no desinfecta los nombres de archivo proporcionados por el usuario, entonces este problema puede explotarse para leer o escribir archivos arbitrarios. Esto afecta a LocalStorageProvider.cs.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-05-30 CVE Reserved
- 2019-08-13 CVE Published
- 2023-07-20 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://security401.com/twentytwenty-storage-path-traversal | 2024-08-04 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Twentytwenty.storage Project Search vendor "Twentytwenty.storage Project" | Twentytwenty.storage Search vendor "Twentytwenty.storage Project" for product "Twentytwenty.storage" | 2.11.0 Search vendor "Twentytwenty.storage Project" for product "Twentytwenty.storage" and version "2.11.0" | - |
Affected
|