Falcon web server 2.0.0.1021 and earlier allows remote attackers to bypass access restrictions for protected files via a URL whose directory portion ends in a . (dot).
| Software | From | Fixed in |
|---|---|---|
| blueface / falcon_web_server | 2.0.0.1021 | 2.0.0.1021.x |
| blueface / falcon_web_server | 2.0.0.1021_ssl | 2.0.0.1021_ssl.x |