CVE-2021-43795
In affected versions an attacker can access an Armeria server's local file system beyond its restricted directory by sending an HTTP request whose path contains `%2F` (encoded `/`), such as `/files/..%2Fsecrets.txt`, bypassing Armeria's path validation…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.64%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Armeria is an open source microservice framework. In affected versions an attacker can access an Armeria server's local file system beyond its restricted directory by sending an HTTP request whose path contains `%2F` (encoded `/`), such as `/files/..%2Fsecrets.txt`, bypassing Armeria's path validation logic. Armeria 1.13.4 or above contains the hardened path validation logic that handles `%2F` properly. This vulnerability can be worked around by inserting a decorator that performs an additional validation on the request path.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.64% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- linecorp/armeria
- Source
- security-advisories@github.com
References
- https://github.com/line/armeria/commit/e2697a575e9df6692b423e02d731f293c1313284Patch, Third Party Advisory
- https://github.com/line/armeria/pull/3855Third Party Advisory
- https://github.com/line/armeria/security/advisories/GHSA-8fp4-rp6c-5gcvThird Party Advisory
- https://github.com/line/armeria/commit/e2697a575e9df6692b423e02d731f293c1313284Patch, Third Party Advisory
- https://github.com/line/armeria/pull/3855Third Party Advisory
- https://github.com/line/armeria/security/advisories/GHSA-8fp4-rp6c-5gcvThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.