Falcon web server 2.0.0.1020 and earlier allows remote attackers to bypass authentication and read restricted files via an extra / (slash) in the requested URL.
| Software | From | Fixed in |
|---|---|---|
| blueface / falcon_web_server | 2.0.0.1020 | 2.0.0.1020.x |
| blueface / falcon_web_server | 2.0.0.1009 | 2.0.0.1009.x |