CVE-2021-32769
Summary
| CVE | CVE-2021-32769 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-16 19:15:00 UTC |
| Updated | 2021-07-27 16:44:00 UTC |
| Description | Micronaut is a JVM-based, full stack Java framework designed for building JVM applications. A path traversal vulnerability exists in versions prior to 2.5.9. With a basic configuration, it is possible to access any file from a filesystem, using "/../../" in the URL. This occurs because Micronaut does not restrict file access to configured paths. The vulnerability is patched in version 2.5.9. As a workaround, do not use `**` in mapping, use only `*`, which exposes only flat structure of a directory not allowing traversal. If using Linux, another workaround is to run micronaut in chroot. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Merge pull request from GHSA-cjx7-399x-p2rj · micronaut-projects/micronaut-core@a0cfeb1 · GitHub |
MISC |
github.com |
|
| Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in micronaut-core · Advisory · micronaut-projects/micronaut-core · GitHub |
CONFIRM |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981958 Java (maven) Security Update for io.micronaut:micronaut-http-server-netty (GHSA-cjx7-399x-p2rj)