First published: Thu Oct 15 2020(Updated: )
In Eclipse Vert.x 3.4.x up to 3.9.4, 4.0.0.milestone1, 4.0.0.milestone2, 4.0.0.milestone3, 4.0.0.milestone4, 4.0.0.milestone5, 4.0.0.Beta1, 4.0.0.Beta2, and 4.0.0.Beta3, StaticHandler doesn't correctly processes back slashes on Windows Operating systems, allowing, escape the webroot folder to the current working directory.
Credit: emo@eclipse.org
Affected Software | Affected Version | How to fix |
---|---|---|
Eclipse Vert.x | >=3.4.0<=3.9.4 | |
Eclipse Vert.x | =4.0.0-beta1 | |
Eclipse Vert.x | =4.0.0-beta2 | |
Eclipse Vert.x | =4.0.0-beta3 | |
Eclipse Vert.x | =4.0.0-milestone1 | |
Eclipse Vert.x | =4.0.0-milestone2 | |
Eclipse Vert.x | =4.0.0-milestone3 | |
Eclipse Vert.x | =4.0.0-milestone4 | |
Eclipse Vert.x | =4.0.0-milestone5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.