{"id":"GHSA-px9h-x66r-8mpc","summary":"path traversal in Jooby","details":"### Impact\nAccess to sensitive information available from classpath. \n\n### Patches\nPatched version: 1.6.7 and 2.8.2\n\nCommit 1.x: https://github.com/jooby-project/jooby/commit/34f526028e6cd0652125baa33936ffb6a8a4a009\n\nCommit 2.x: https://github.com/jooby-project/jooby/commit/c81479de67036993f406ccdec23990b44b0bec32\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\n### References\n\nLatest 1.x version: 1.6.6\n\n#### Arbitrary class path resource access 1\nWhen sharing a *File System* directory as in:\n\n``` java\nassets(\"/static/**\", Paths.get(\"static\"));\n```\n\nThe class path is also searched for the file (`org.jooby.handlers.AssetHandler.loader`):\n[jooby/AssetHandler.java at 1.x · jooby-project/jooby · GitHub](https://github.com/jooby-project/jooby/blob/1.x/jooby/src/main/java/org/jooby/handlers/AssetHandler.java)\n\n``` java\n  private static Loader loader(final Path basedir, final ClassLoader classloader) {\n    if (Files.exists(basedir)) {\n      return name -\u003e {\n        Path path = basedir.resolve(name).normalize();\n        if (Files.exists(path) && path.startsWith(basedir)) {\n          try {\n            return path.toUri().toURL();\n          } catch (MalformedURLException x) {\n            // shh\n          }\n        }\n        return classloader.getResource(name);\n      };\n    }\n    return classloader::getResource;\n  }\n```\n\nIf we send `/static/WEB-INF/web.xml` it will fail to load it from the file system but will go into `classloader.getResource(name)` where name equals `/WEB-INF/web.xml` so will succeed and return the requested file. This way we can get any configuration file or even the application class files\n\nIf assets are configured for a certain extension we can still bypass it. eg:\n\n```java\nassets(\"/static/**/*.js\", Paths.get(\"static\"));\n```\n\nWe can send:\n\n```\nhttp://localhost:8080/static/io/yiss/App.class.js\n```\n\n#### Arbitrary class path resource access 2\nThis vulnerability also affects assets configured to access resources from the root of the class path. eg:\n\n```java\nassets(\"/static/**\");\n```\n\nIn this case we can traverse `static` by sending:\n\n```\nhttp://localhost:8080/static/..%252fio/yiss/App.class\n```\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [jooby](https://github.com/jooby-project/jooby/issues)\n* Email us at [support@jooby.io](mailto:support@jooby.io)","aliases":["CVE-2020-7647"],"modified":"2025-01-14T08:57:27.236187Z","published":"2020-05-13T16:29:26Z","database_specific":{"github_reviewed_at":"2020-05-12T20:27:09Z","nvd_published_at":null,"cwe_ids":["CWE-22"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/jooby-project/jooby/security/advisories/GHSA-px9h-x66r-8mpc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-7647"},{"type":"WEB","url":"https://github.com/jooby-project/jooby/commit/34f526028e6cd0652125baa33936ffb6a8a4a009"},{"type":"PACKAGE","url":"https://github.com/jooby-project/jooby"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-IOJOOBY-568806"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-IOJOOBY-568806,"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-ORGJOOBY-568807"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-ORGJOOBY-568807,"}],"affected":[{"package":{"name":"io.jooby:jooby","ecosystem":"Maven","purl":"pkg:maven/io.jooby/jooby"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.8.2"}]}],"versions":["2.0.0","2.0.0.M1","2.0.0.M2","2.0.0.M3","2.0.0.RC1","2.0.0.RC2","2.0.0.RC3","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.1.0","2.2.0","2.2.1","2.3.0","2.3.1","2.4.0","2.5.0","2.5.1","2.6.0","2.6.1","2.6.2","2.7.0","2.7.1","2.7.2","2.7.3","2.8.0","2.8.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/05/GHSA-px9h-x66r-8mpc/GHSA-px9h-x66r-8mpc.json"}},{"package":{"name":"org.jooby:jooby","ecosystem":"Maven","purl":"pkg:maven/org.jooby/jooby"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.8.2"}]}],"versions":["0.1.0","0.10.0","0.11.0","0.11.1","0.11.2","0.12.0","0.13.0","0.13.1","0.14.0","0.15.0","0.15.1","0.16.0","0.2.0","0.2.1","0.3.0","0.4.0","0.4.1","0.4.2","0.4.2.1","0.5.0","0.5.1","0.5.2","0.5.3","0.6.0","0.6.1","0.6.2","0.6.3","0.6.4","0.7.0","0.8.0","0.8.1","0.8.2","0.9.0","0.9.1","0.9.2","1.0.0","1.0.0.CR1","1.0.0.CR2","1.0.0.CR3","1.0.0.CR4","1.0.0.CR5","1.0.0.CR6","1.0.0.CR7","1.0.0.CR8","1.0.1","1.0.2","1.0.3","1.1.0","1.1.1","1.1.2","1.1.3","1.2.0","1.2.1","1.2.2","1.2.3","1.3.0","1.4.0","1.4.1","1.5.0","1.5.1","1.6.0","1.6.1","1.6.2","1.6.3","1.6.4","1.6.5","1.6.6","1.6.7","1.6.8","1.6.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/05/GHSA-px9h-x66r-8mpc/GHSA-px9h-x66r-8mpc.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}