CVE-2018-12542

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
10/10/2018
Last modified:
07/11/2023

Description

In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '\' (forward slashes) sequences that can resolve to a location that is outside of that directory when running on Windows Operating Systems.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:eclipse:vert.x:*:*:*:*:*:*:*:* 3.0.0 (including) 3.5.3 (including)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*