QID 981073
QID 981073: Java (maven) Security Update for io.vertx:vertx-web (GHSA-h39x-m55c-v55h)
In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '\' (forward slashes) sequences that can resolve to a location that is outside of that directory when running on Windows Operating Systems.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-h39x-m55c-v55h for updates pertaining to this vulnerability.
Vendor References
- GHSA-h39x-m55c-v55h -
github.com/advisories/GHSA-h39x-m55c-v55h
CVEs related to QID 981073
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-h39x-m55c-v55h | io.vertx:vertx-web |
|