GHSA-53jx-vvf9-4x38
StaticHandler disclosure of classpath resources on Windows when mounted on a wildcard route
Quick fix
GHSA-53jx-vvf9-4x38 — io.vertx:vertx-web: upgrade to the fixed version with the command below.
# pom.xml: bump <version>4.3.8</version> for io.vertx:vertx-webDetails
### Summary
When running vertx web applications that serve files using `StaticHandler` on Windows Operating Systems and Windows File Systems, if the mount point is a wildcard (`*`) then an attacker can exfiltrate any class path resource.
### Details When computing the relative path to locate the resource, in case of wildcards, the code:
https://github.com/vert-x3/vertx-web/blob/62c0d66fa1c179ae6a4d57344631679a2b97e60f/vertx-web/src/main/java/io/vertx/ext/web/impl/Utils.java#L83
returns the user input (without validation) as the segment to lookup. Even though checks are performed to avoid escaping the sandbox, given that the input was not sanitized `\` are not properly handled and an attacker can build a path that is valid within the classpath.
### PoC
https://github.com/adrien-aubert-drovio/vertx-statichandler-windows-traversal-path-vulnerability
Are you affected?
Enter the version of the package you're using.
Affected packages
4.0.0Fixed in: 4.3.8# pom.xml: bump <version>4.3.8</version> for io.vertx:vertx-webReferences
- https://github.com/vert-x3/vertx-web/security/advisories/GHSA-53jx-vvf9-4x38[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-24815[ADVISORY]
- https://github.com/vert-x3/vertx-web/commit/9e3a783b1d1a731055e9049078b1b1494ece9c15[WEB]
- https://github.com/vert-x3/vertx-web[PACKAGE]
- https://github.com/vert-x3/vertx-web/blob/62c0d66fa1c179ae6a4d57344631679a2b97e60f/vertx-web/src/main/java/io/vertx/ext/web/impl/Utils.java#L83[WEB]