PT-2025-7670 · Unknown · Opensolon Solon

F10Wers13Eicheng

·

Published

2025-02-23

·

Updated

2025-02-23

·

CVE-2025-1584

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions opensolon Solon versions up to 3.0.8
Description A vulnerability was found in the Solon Web Static Files component, affecting the file StaticMappings.java. The manipulation leads to path traversal, allowing an attacker to access files outside the intended directory using '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Recommendations For opensolon Solon versions up to 3.0.8, upgrade to version 3.0.9 to address this issue. As a temporary workaround, consider restricting access to the vulnerable StaticMappings.java file until the patch is applied.

Exploit

Fix

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-1584
GHSA-X8Q6-CCHR-P7M6

Affected Products

Opensolon Solon