com.bertramlabs.plugins:asset-pipeline-servlet@2.14.0 vulnerabilities

  • latest version

    5.0.8

  • latest non vulnerable version

  • first published

    9 years ago

  • latest version published

    15 days ago

  • licenses detected

  • package manager

  • Direct Vulnerabilities

    Known vulnerabilities in the com.bertramlabs.plugins:asset-pipeline-servlet package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Directory Traversal

    com.bertramlabs.plugins:asset-pipeline-servlet is an asset pipeline for the jvm

    Affected versions of this package are vulnerable to Directory Traversal in AssetPipelineFilter.groovy and AssetPipelineFilterCore.groovy that allows attackers to read unintended files on the target file system.

    How to fix Directory Traversal?

    Upgrade com.bertramlabs.plugins:asset-pipeline-servlet to version 3.0.4 or higher.

    [,3.0.4)
    • H
    Directory Traversal

    com.bertramlabs.plugins:asset-pipeline-servlet is an asset pipeline for the jvm

    Affected versions of this package are vulnerable to Directory Traversal that allows attackers to access and download arbitrary files, including .class files, by passing the path to each file in a GET request.

    NOTE: This vulnerability is only exploitable for applications deployed with Jetty.

    How to fix Directory Traversal?

    Upgrade com.bertramlabs.plugins:asset-pipeline-servlet to version 2.14.1, 3.0.6 or higher.

    [,2.14.1)[3.0.0,3.0.6)