Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 04 Oct 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Weaver
Weaver e-bridge |
|
| Vendors & Products |
Weaver
Weaver e-bridge |
Fri, 02 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 02 Oct 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Weaver e-Bridge contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to access arbitrary files on the host system by supplying a file: URL to the downloadUrl parameter of the saveYZJFile endpoint. Attackers can exploit this flaw to read sensitive files such as /etc/passwd or configuration and credential files, and the same endpoint's support for http(s) URLs also enables server-side request forgery against internal network resources. Exploitation evidence was first observed by the Shadowserver Foundation on 2023-10-17. | |
| Title | Weaver e-Bridge Unauthenticated Arbitrary File Read via saveYZJFile | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-02T20:14:15.156Z
Reserved: 2026-10-02T15:31:54.866Z
Link: CVE-2020-37278
Updated: 2026-10-02T20:14:12.104Z
Status : Deferred
Published: 2026-10-02T19:16:38.703
Modified: 2026-10-06T16:08:43.180
Link: CVE-2020-37278
No data.
OpenCVE Enrichment
Updated: 2026-10-04T20:53:25Z
-
CWE-918
Server-Side Request Forgery (SSRF)