PT-2018-14078 · Grails · Grails Asset Pipeline Plugin

Ricterz

·

Publicado

2018-09-28

·

Atualizado

2022-05-14

·

CVE-2018-17605

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Grails Asset Pipeline plugin versions prior to 3.0.4
Description An issue was discovered that allows an attacker to perform directory traversal via a crafted request when a servlet-based application is executed in Jetty. This is due to a classloader vulnerability that can allow a reverse file traversal route in AssetPipelineFilter.groovy or AssetPipelineFilterCore.groovy.
Recommendations For Grails Asset Pipeline plugin versions prior to 3.0.4, update to version 3.0.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the AssetPipelineFilter.groovy and AssetPipelineFilterCore.groovy files to minimize the risk of exploitation.

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-17605
GHSA-G7WM-22M6-5774

Produtos afetados

Grails Asset Pipeline Plugin