CVE-2020-36559

HIGH

aah < 0.12.4 - Path Traversal via HTTPEngine.Handle

Title source: llm
STIX 2.1

Description

Due to improper sanitization of user input, HTTPEngine.Handle allows for directory traversal, allowing an attacker to read files outside of the target directory that the server has permission to read.

References (4)

Core 4

Scores

CVSS v3 7.5
EPSS 0.0114
EPSS Percentile 62.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (3)
aahframework/aah < 0.12.4
Go/aahframe.work 0 - 0.12.4Go
go-aah/aah 0 - 0.12.4Go
Published Dec 27, 2022
Tracked Since Feb 18, 2026