Path traversal in Retrofit - CVE-2018-1000850
Published: November 20, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences when processing POST, PUT or DELETE requests within the addPathParameter() method in RequestBuilder class. A remote attacker can trick the victim to follow a specially crafted URL and gain access to otherwise restricted resources.
Affected software
Fuse
IBM Business Automation Manager Open Editions
How to mitigate CVE-2018-1000850
Fuse - update to 7.5.0
IBM Business Automation Manager Open Editions - update to 8.0.8
External References
- https://github.com/square/retrofit/blob/master/CHANGELOG.md
- https://github.com/square/retrofit/commit/b9a7f6ad72073ddd40254c0058710e87a073047d#diff-943ec7ed35e68201824904d1dc0ec982
- https://ihacktoprotect.com/post/retrofit-path-traversal/
- https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E
- https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E