CVE-2020-21522: Halo
Critical severity, CVSS 9.8. EPSS: 1.5% chance of exploitation in the next 30 days.
An issue was discovered in halo V1.1.3. A Zip Slip Directory Traversal Vulnerability in the backend,the attacker can overwrite some files, such as ftl files, .bashrc files in the user directory, and finally get the permissions of the operating system.
Affected products
- Halo Halo: version 1.1.3 only
Published 2020-09-30. Last modified 2026-06-17.