{ "schema_version": "1.4.0", "id": "GHSA-8g8c-49hq-vg6g", "modified": "2024-04-04T04:03:34Z", "published": "2023-05-12T12:30:18Z", "aliases": [ "CVE-2020-13377" ], "details": "The web-services interface of Loadbalancer.org Enterprise VA MAX through 8.3.8 could allow an authenticated, remote, low-privileged attacker to conduct directory traversal attacks and obtain read and write access to sensitive files.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N" } ], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2020-13377" }, { "type": "WEB", "url": "https://inf0seq.github.io/cve/2020/04/21/Path-Traversal-in-Enterprise-loadbalancer-VA-MAX-v8.3.8-and-earlier.html" }, { "type": "WEB", "url": "https://www.loadbalancer.org/products/virtual/enterprise-va-max" } ], "database_specific": { "cwe_ids": [ "CWE-22" ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2023-05-12T11:15:12Z" } }