GHSA-wvp2-9ppw-337j
Paths contain matrix variables bypass decorators
Quick fix
GHSA-wvp2-9ppw-337j — com.linecorp.armeria:armeria: upgrade to the fixed version with the command below.
# pom.xml: bump <version>1.24.3</version> for com.linecorp.armeria:armeriaDetails
### Impact Spring supports [Matrix variables](https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-controller/ann-methods/matrix-variables.html). When Spring integration is used, Armeria calls Spring controllers via `TomcatService` or `JettyService` with the path that may contain matrix variables. In this situation, the Armeria decorators might not invoked because of the matrix variables. Let's see the following example: ``` // Spring controller @GetMapping("/important/resources") public String important() {...}
// Armeria decorator ServerBuilder sb = ... sb.decoratorUnder("/important/", authService); ``` If an attacker sends a request with `/important;a=b/resources`, the request would bypass the authrorizer
### Patches - https://github.com/line/armeria-ghsa-wvp2-9ppw-337j/commit/9b0ec3e099cc05fbff11d7f1012a1dddb0000d0c
### Workarounds Users can add decorators using regex. `e.g. "regex:^/important.*"`
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.24.3# pom.xml: bump <version>1.24.3</version> for com.linecorp.armeria:armeriaReferences
- https://github.com/line/armeria/security/advisories/GHSA-wvp2-9ppw-337j[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-38493[ADVISORY]
- https://github.com/line/armeria/commit/039db50bbfc88014ea8737fd1e1ddd6fd3fc4f07[WEB]
- https://github.com/line/armeria/commit/49e04ef231ad65750739529c7fa4ce946ff7588b[WEB]
- https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-controller/ann-methods/matrix-variables.html[WEB]
- https://github.com/line/armeria[PACKAGE]