PT-2018-14078 · Grails · Grails Asset Pipeline Plugin

Ricterz

·

Published

2018-09-28

·

Updated

2022-05-14

·

CVE-2018-17605

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Grails Asset Pipeline plugin versions prior to 3.0.4
Description An issue was discovered that allows an attacker to perform directory traversal via a crafted request when a servlet-based application is executed in Jetty. This is due to a classloader vulnerability that can allow a reverse file traversal route in AssetPipelineFilter.groovy or AssetPipelineFilterCore.groovy.
Recommendations For Grails Asset Pipeline plugin versions prior to 3.0.4, update to version 3.0.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the AssetPipelineFilter.groovy and AssetPipelineFilterCore.groovy files to minimize the risk of exploitation.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-17605
GHSA-G7WM-22M6-5774

Affected Products

Grails Asset Pipeline Plugin