Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder class, method addPathParameter that can result in By manipulating the URL an attacker could add or delete resources otherwise unavailable to her.. This attack appear to be exploitable via An attacker should have access to an encoded path parameter on POST, PUT or DELETE request.. This vulnerability appears to have been fixed in 2.5.0 and later.
oryginał ENCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NSquareup Retrofit
APPSquareup2.0.0 – 2.5.0 (bez)
Powiązane podatności
XXE w Squareup Retrofit umożliwiające odczyt plików i SSRF
Command injection w Squareup git-fastclone — wykonanie dowolnych poleceń
Wire (gRPC/protobuf): brak walidacji długości pola powoduje crash usługi
git-fastclone before 1.0.1 permits arbitrary shell command execution from .gitmodules. If an attacker can inst...
A flaw was found in Red Hat's AMQ-Streams, which ships a version of the OKHttp component with an information d...