Path traversal in Vert.x-Web - CVE-2023-24815
Published: June 22, 2023
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences, when running vertx web applications that serve files using `StaticHandler` on Windows Operating Systems and Windows File Systems, if the mount point is a wildcard (`*`). A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.
Affected software
IBM Cloud Pak for Watson AIOps
IBM Application Suite - IBM Asset Data Dictionary Component
Dell Data Protection Central
Red Hat Camel for Spring Boot
Cryostat
IBM Cloud Pak for Business Automation
How to mitigate CVE-2023-24815
Red Hat Camel for Spring Boot - update to 3.20.1 Patch 1
Cryostat - update to 2.4.0
IBM Application Suite - IBM Asset Data Dictionary Component - addressed in versions 8.9.9, 8.10.4
Dell Data Protection Central - update to 19.11.0-2
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3.24, 23.0.1.2
External References
- https://github.com/vert-x3/vertx-web/commit/9e3a783b1d1a731055e9049078b1b1494ece9c15
- https://github.com/vert-x3/vertx-web/security/advisories/GHSA-53jx-vvf9-4x38
- https://github.com/vert-x3/vertx-web/blob/62c0d66fa1c179ae6a4d57344631679a2b97e60f/vertx-web/src/main/java/io/vertx/ext/web/impl/Utils.java#L83
Related Security Bulletins
- Path traversal in Vert.x-Web
- Multiple vulnerabilities in Red Hat Integration Camel for Spring Boot 3.20
- Path traversal in IBM Maximo Application Suite
- Multiple vulnerabilities in IBM Cloud Pak for Business Automation
- Multiple vulnerabilities in IBM Cloud Pak for Watson AIOps
- Multiple vulnerabilities in Red Hat build of Cryostat
- Multiple vulnerabilities in Dell Data Protection Central