Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-43795

Опубликовано: 02 дек. 2021
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Низкий

Описание

Armeria is an open source microservice framework. In affected versions an attacker can access an Armeria server's local file system beyond its restricted directory by sending an HTTP request whose path contains %2F (encoded /), such as /files/..%2Fsecrets.txt, bypassing Armeria's path validation logic. Armeria 1.13.4 or above contains the hardened path validation logic that handles %2F properly. This vulnerability can be worked around by inserting a decorator that performs an additional validation on the request path.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:linecorp:armeria:*:*:*:*:*:*:*:*
Версия до 1.13.4 (исключая)

EPSS

Процентиль: 73%
0.00754
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
github
около 4 лет назад

Path Traversal in com.linecorp.armeria:armeria

EPSS

Процентиль: 73%
0.00754
Низкий

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-22