[MAVEN:GHSA-G7WM-22M6-5774] Asset Pipeline plugin for Grails vulnerable to Path Traversal

Severity High
Affected Packages 1
Fixed Packages 1
CVEs 1

An issue was discovered in the Asset Pipeline plugin before 3.0.4 for Grails. An attacker can perform directory traversal via a crafted request when a servlet-based application is executed in Jetty, because there is a classloader vulnerability that can allow a reverse file traversal route in AssetPipelineFilter.groovy or AssetPipelineFilterCore.groovy.

Package Affected Version
pkg:maven/org.grails.plugins/asset-pipeline < 3.0.4
Package Fixed Version
pkg:maven/org.grails.plugins/asset-pipeline = 3.0.4
ID
MAVEN:GHSA-G7WM-22M6-5774
Severity
high
URL
https://github.com/advisories/GHSA-g7wm-22m6-5774
Published
2022-05-14T01:44:59
(2 years ago)
Modified
2023-02-02T05:03:36
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.grails.plugins/asset-pipeline org.grails.plugins asset-pipeline < 3.0.4
Fixed pkg:maven/org.grails.plugins/asset-pipeline org.grails.plugins asset-pipeline = 3.0.4
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...