{"id":"GHSA-8j39-fgfp-vxh8","summary":"XXL-CONF Path Traversal vulnerability","details":"An issue was discovered in XXL-CONF 1.6.0. There is a path traversal vulnerability via `../` in the keys parameter that can download any configuration file, related to `ConfController.java` and `PropUtil.java`.","aliases":["CVE-2018-20094"],"modified":"2023-11-08T04:00:10.783610Z","published":"2018-12-19T19:25:04Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-06-16T21:25:45Z","nvd_published_at":null,"cwe_ids":["CWE-22"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-20094"},{"type":"WEB","url":"https://github.com/xuxueli/xxl-conf/issues/61"},{"type":"PACKAGE","url":"https://github.com/xuxueli/xxl-conf"},{"type":"WEB","url":"https://github.com/xuxueli/xxl-conf/blob/6726dfe7979ea6d8fb983771471cde69789de632/xxl-conf-admin/src/main/java/com/xxl/conf/admin/controller/ConfController.java"}],"affected":[{"package":{"name":"com.xuxueli:xxl-conf-admin","ecosystem":"Maven","purl":"pkg:maven/com.xuxueli/xxl-conf-admin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.6.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/12/GHSA-8j39-fgfp-vxh8/GHSA-8j39-fgfp-vxh8.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}