CVE-2023-38493

CVSS V2 None CVSS V3 None
Description
Armeria is a microservice framework Spring supports Matrix variables. When Spring integration is used, Armeria calls Spring controllers via `TomcatService` or `JettyService` with the path that may contain matrix variables. Prior to version 1.24.3, the Armeria decorators might not invoked because of the matrix variables. If an attacker sends a specially crafted request, the request may bypass the authorizer. Version 1.24.3 contains a patch for this issue.
Overview
  • CVE ID
  • CVE-2023-38493
  • Assigner
  • GitHub_M
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-07-25T20:51:11.170Z
  • Last Modified Date
  • 2023-07-25T20:51:11.170Z
History
Created Old Value New Value Data Type Notes
2024-06-25 21:27:59 Added to TrackCVE