CVE-2021-32769: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in micronaut-core
Micronaut is a JVM-based, full stack Java framework designed for building JVM applications. A path traversal vulnerability exists in versions prior to 2.5.9. With a basic configuration, it is possible to access any file from a filesystem, using "/../../" in the URL. This occurs because Micronaut does not restrict file access to configured paths. The vulnerability is patched in version 2.5.9. As a workaround, do not use in mapping, use only , which exposes only flat structure of a directory not allowing traversal. If using Linux, another workaround is to run micronaut in chroot.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this Micronaut vulnerability?
The vulnerability ID for this Micronaut vulnerability is CVE-2021-32769.
What is Micronaut?
Micronaut is a JVM-based, full stack Java framework designed for building JVM applications.
What is the severity of CVE-2021-32769?
The severity of CVE-2021-32769 is high with a severity value of 7.5.
How does the path traversal vulnerability in Micronaut occur?
The path traversal vulnerability in Micronaut occurs because it is possible to access any file from a filesystem using "/../../" in the URL.
How can I fix the path traversal vulnerability in Micronaut?
To fix the path traversal vulnerability in Micronaut, you should update to version 2.5.9 or later.