CVE-2018-1000850
retrofit: Directory traversal in RequestBuilder allows manipulation of resources
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder class, method addPathParameter that can result in By manipulating the URL an attacker could add or delete resources otherwise unavailable to her.. This attack appear to be exploitable via An attacker should have access to an encoded path parameter on POST, PUT or DELETE request.. This vulnerability appears to have been fixed in 2.5.0 and later.
Square Retrofit, desde la versión 2.0 (incluida) y 2.5.0 (excluida), contiene una vulnerabilidad de salto de directorio en la clase RequestBuilder, método addPathParameter. Al manipular la URL, un atacante podría añadir o eliminar recursos que no estarían disponibles. Para que el ataque sea explotable, un atacante debería tener acceso a un parámetro path cifrado en las peticiones POST, PUT o DELETE. La vulnerabilidad parece haber sido solucionada en las versiones 2.5.0 y siguientes.
A flaw was found in Retrofit, where it allowed directory traversal via its RequestBuilder class. An attacker could use this flaw to access information or commands outside of its set permissions.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-11-25 CVE Reserved
- 2018-12-20 CVE Published
- 2024-05-12 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (9)
URL | Date | SRC |
---|---|---|
https://ihacktoprotect.com/post/retrofit-path-traversal | 2024-08-05 |
URL | Date | SRC |
---|---|---|
https://github.com/square/retrofit/commit/b9a7f6ad72073ddd40254c0058710e87a073047d#diff-943ec7ed35e68201824904d1dc0ec982 | 2023-11-07 |
URL | Date | SRC |
---|---|---|
https://access.redhat.com/errata/RHSA-2019:3892 | 2023-11-07 | |
https://access.redhat.com/security/cve/CVE-2018-1000850 | 2019-11-14 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1663904 | 2019-11-14 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Squareup Search vendor "Squareup" | Retrofit Search vendor "Squareup" for product "Retrofit" | >= 2.0.0 < 2.5.0 Search vendor "Squareup" for product "Retrofit" and version " >= 2.0.0 < 2.5.0" | - |
Affected
|