Description
In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '\' (forward slashes) sequences that can resolve to a location that is outside of that directory when running on Windows Operating Systems.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0608 | In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '\' (forward slashes) sequences that can resolve to a location that is outside of that directory when running on Windows Operating Systems. |
Github GHSA |
GHSA-h39x-m55c-v55h | Eclipse Vert.x does not properly neutralize '' (forward slashes) sequences that can resolve to an external location |
References
History
No history.
Status: PUBLISHED
Assigner: eclipse
Published:
Updated: 2024-08-05T08:38:06.140Z
Reserved: 2018-06-18T00:00:00.000Z
Link: CVE-2018-12542
No data.
Status : Modified
Published: 2018-10-10T20:29:00.553
Modified: 2024-11-21T03:45:24.253
Link: CVE-2018-12542
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA