CVE-2021-32769
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
16/07/2021
Last modified:
27/07/2021
Description
Micronaut is a JVM-based, full stack Java framework designed for building JVM applications. A path traversal vulnerability exists in versions prior to 2.5.9. With a basic configuration, it is possible to access any file from a filesystem, using "/../../" in the URL. This occurs because Micronaut does not restrict file access to configured paths. The vulnerability is patched in version 2.5.9. As a workaround, do not use `**` in mapping, use only `*`, which exposes only flat structure of a directory not allowing traversal. If using Linux, another workaround is to run micronaut in chroot.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:objectcomputing:micronaut:*:*:*:*:*:*:*:* | 2.5.9 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



