TROYANOSYVIRUS
Back to CVEs

CVE-2019-15630

N/A

Description

Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before August 1 2019, MuleSoft Mule Runtime 4.1.0 and higher released before August 1 2019, and all versions of MuleSoft API Gateway released before August 1 2019 allow remote attackers to read files accessible to the Mule process.

CVE Details

CVSS v3.1 ScoreN/A
Published8/30/2019
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0

Affected Products

mulesoft:api_gatewaymulesoft:mule_runtime

Weaknesses (CWE)

CWE-22

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.