CVE-2020-10560 - OSSN Arbitrary File Read
Exploiting Arbitrary file read and poor crypto in OSSN.
This is a fairly detailed blog post on the pain we went through to get Arbitrary File Read (CVE-2020-10560) in an open-source platform that involved writing a custom crypto cracking tool!. Before we get to that let's start at the beginning.
OSSN
