QID 981186
QID 981186: Java (maven) Security Update for com.squareup.retrofit2:retrofit (GHSA-8p8g-f9vg-r7xr)
Square Retrofit versions from (including) 2.0 to 2.5.0 (excluding) contain a Directory Traversal vulnerability in RequestBuilder class, method addPathParameter. By manipulating the URL an attacker could add or delete resources otherwise unavailable to her. This attack appears to be exploitable via an encoded path parameter on POST, PUT or DELETE request. This vulnerability appears to have been fixed in 2.5.0 and later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-8p8g-f9vg-r7xr for updates pertaining to this vulnerability.
Vendor References
- GHSA-8p8g-f9vg-r7xr -
github.com/advisories/GHSA-8p8g-f9vg-r7xr
CVEs related to QID 981186
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-8p8g-f9vg-r7xr | com.squareup.retrofit2:retrofit |
|