VDB
Sign up
HIGH7.5

GHSA-wvp2-9ppw-337j

Paths contain matrix variables bypass decorators

Quick fix

GHSA-wvp2-9ppw-337j — com.linecorp.armeria:armeria: upgrade to the fixed version with the command below.

# pom.xml: bump <version>1.24.3</version> for com.linecorp.armeria:armeria

Details

### Impact Spring supports [Matrix variables](https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-controller/ann-methods/matrix-variables.html). When Spring integration is used, Armeria calls Spring controllers via `TomcatService` or `JettyService` with the path that may contain matrix variables. In this situation, the Armeria decorators might not invoked because of the matrix variables. Let's see the following example: ``` // Spring controller @GetMapping("/important/resources") public String important() {...}

// Armeria decorator ServerBuilder sb = ... sb.decoratorUnder("/important/", authService); ``` If an attacker sends a request with `/important;a=b/resources`, the request would bypass the authrorizer

### Patches - https://github.com/line/armeria-ghsa-wvp2-9ppw-337j/commit/9b0ec3e099cc05fbff11d7f1012a1dddb0000d0c

### Workarounds Users can add decorators using regex. `e.g. "regex:^/important.*"`

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/com.linecorp.armeria:armeria
Introduced in: 0Fixed in: 1.24.3
Fix# pom.xml: bump <version>1.24.3</version> for com.linecorp.armeria:armeria

References