In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '\' (forward slashes) sequences that can resolve to a location that is outside of that directory when running on Windows Operating Systems.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-0608 In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '\' (forward slashes) sequences that can resolve to a location that is outside of that directory when running on Windows Operating Systems.
Github GHSA Github GHSA GHSA-h39x-m55c-v55h Eclipse Vert.x does not properly neutralize '' (forward slashes) sequences that can resolve to an external location
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: eclipse

Published:

Updated: 2024-08-05T08:38:06.140Z

Reserved: 2018-06-18T00:00:00

Link: CVE-2018-12542

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-10-10T20:29:00.553

Modified: 2024-11-21T03:45:24.253

Link: CVE-2018-12542

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.