CVE Published: 30/08/2019 |
CVE Updated: 05/08/2024 |
CVE Year: 2019 Source: Salesforce |
Vendor: Salesforce, Inc. |
Product: Mulesoft Status : PUBLISHED
CVE-2019-15630 Description
Directory Traversal in APIkit, HTTP connector, and OAuth2 Provider components in MuleSoft Mule Runtime 3.2.0 and higher released before August 1 2019, MuleSoft Mule Runtime 4.1.0 and higher released before August 1 2019, and all versions of MuleSoft API Gateway released before August 1 2019 allow remote attackers to read files accessible to the Mule process.