CVE-2023-38493
CVSS V2 None
CVSS V3 None
Description
Armeria is a microservice framework Spring supports Matrix variables. When Spring integration is used, Armeria calls Spring controllers via `TomcatService` or `JettyService` with the path that may contain matrix variables. Prior to version 1.24.3, the Armeria decorators might not invoked because of the matrix variables. If an attacker sends a specially crafted request, the request may bypass the authorizer. Version 1.24.3 contains a patch for this issue.
Overview
- CVE ID
- CVE-2023-38493
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2023-07-25T20:51:11.170Z
- Last Modified Date
- 2023-07-25T20:51:11.170Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/line/armeria/security/advisories/GHSA-wvp2-9ppw-337j | x_refsource_CONFIRM |
https://github.com/line/armeria/commit/039db50bbfc88014ea8737fd1e1ddd6fd3fc4f07 | x_refsource_MISC |
https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-controller/ann-methods/matrix-variables.html | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2023-38493 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-38493 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-25 21:27:59 | Added to TrackCVE |