Vulnerability Description
In Eclipse Vert.x 3.4.x up to 3.9.4, 4.0.0.milestone1, 4.0.0.milestone2, 4.0.0.milestone3, 4.0.0.milestone4, 4.0.0.milestone5, 4.0.0.Beta1, 4.0.0.Beta2, and 4.0.0.Beta3, StaticHandler doesn't correctly processes back slashes on Windows Operating systems, allowing, escape the webroot folder to the current working directory.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Eclipse | Vert.X | >= 3.4.0, <= 3.9.4 |
Related Weaknesses (CWE)
References
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=567416Vendor Advisory
- https://lists.apache.org/thread.html/r591f6932560c8c46cee87415afed92924a982189fe
- https://lists.apache.org/thread.html/r8383b5e7344a8b872e430ad72241b84b83e9701d27
- https://lists.apache.org/thread.html/r8d863b148efe778ce5f8f961d0cafeda399e681d3f
- https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995
- https://lists.apache.org/thread.html/rfd0ebf8387cfd0b959d1e218797e709793cce51a5e
- https://bugs.eclipse.org/bugs/show_bug.cgi?id=567416Vendor Advisory
- https://lists.apache.org/thread.html/r591f6932560c8c46cee87415afed92924a982189fe
- https://lists.apache.org/thread.html/r8383b5e7344a8b872e430ad72241b84b83e9701d27
- https://lists.apache.org/thread.html/r8d863b148efe778ce5f8f961d0cafeda399e681d3f
- https://lists.apache.org/thread.html/rd0e44e8ef71eeaaa3cf3d1b8b41eb25894372e2995
- https://lists.apache.org/thread.html/rfd0ebf8387cfd0b959d1e218797e709793cce51a5e
FAQ
What is CVE-2019-17640?
CVE-2019-17640 is a vulnerability with a CVSS score of 9.8 (CRITICAL). In Eclipse Vert.x 3.4.x up to 3.9.4, 4.0.0.milestone1, 4.0.0.milestone2, 4.0.0.milestone3, 4.0.0.milestone4, 4.0.0.milestone5, 4.0.0.Beta1, 4.0.0.Beta2, and 4.0.0.Beta3, StaticHandler doesn't correctl...
How severe is CVE-2019-17640?
CVE-2019-17640 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-17640?
Check the references section above for vendor advisories and patch information. Affected products include: Eclipse Vert.X.