CVE-2018-12542
Last modified
CVE-2018-12542 is a vulnerability of currently unknown severity. In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '\' (forward slashes) sequences that can resolve to a location that is outside of that directory when running on Windows Operating Systems.. EPSS estimates a 2.29% chance of exploitation in the next 30 days.
Description
In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '\' (forward slashes) sequences that can resolve to a location that is outside of that directory when running on Windows Operating Systems.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Eclipse | Vert.X | >= 3.0.0, <= 3.5.3 |
References
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=539171Issue Tracking, Vendor Advisory
- https://github.com/vert-x3/vertx-web/issues/1025Exploit, Vendor Advisory
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=539171Issue Tracking, Vendor Advisory
- https://github.com/vert-x3/vertx-web/issues/1025Exploit, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-12542?
How severe is CVE-2018-12542?
How do I fix CVE-2018-12542?
Are you affected by CVE-2018-12542?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
