VYPR
Medium severity5.5NVD Advisory· Published Dec 25, 2022· Updated Jun 17, 2026

CVE-2020-36628

CVE-2020-36628

Description

A vulnerability classified as critical has been found in Calsign APDE. This affects the function handleExtract of the file APDE/src/main/java/com/calsignlabs/apde/build/dag/CopyBuildTask.java of the component ZIP File Handler. The manipulation leads to path traversal. Upgrading to version 0.5.2-pre2-alpha is able to address this issue. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-216747.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Calsign/APDEllm-fuzzy2 versions
    = 0.5.2-pre2-alpha+ 1 more
    • (no CPE)range: = 0.5.2-pre2-alpha
    • (no CPE)range: n/a
  • cpe:2.3:a:android_processing_development_environment_project:android_processing_development_environment:*:*:*:*:*:android:*:*+ 1 more
    • cpe:2.3:a:android_processing_development_environment_project:android_processing_development_environment:*:*:*:*:*:android:*:*range: <0.5.2
    • cpe:2.3:a:android_processing_development_environment_project:android_processing_development_environment:0.5.2:pre1_alpha:*:*:*:android:*:*

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.

CVE-2020-36628 · Medium · VYPR