HIGH
Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before August 1 2019, MuleSoft Mule Runtime 4.1.0 and higher released before August 1 2019, and all versions of MuleSoft API Gateway released before August 1 2019 allow remote attackers to read files accessible to the Mule process
Published Aug 30, 2019
7.5
HIGHCVSS 3.0
EPSS 3.00%
Description
Affected products
Remediation
References (4)
Change history (0)
No recorded changes yet.