Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2171 | Armeria is a microservice framework Spring supports Matrix variables. When Spring integration is used, Armeria calls Spring controllers via `TomcatService` or `JettyService` with the path that may contain matrix variables. Prior to version 1.24.3, the Armeria decorators might not invoked because of the matrix variables. If an attacker sends a specially crafted request, the request may bypass the authorizer. Version 1.24.3 contains a patch for this issue. |
Github GHSA |
GHSA-wvp2-9ppw-337j | Paths contain matrix variables bypass decorators |
Thu, 03 Oct 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-10-03T18:47:47.744Z
Reserved: 2023-07-18T16:28:12.076Z
Link: CVE-2023-38493
Updated: 2024-08-02T17:46:55.075Z
Status : Modified
Published: 2023-07-25T21:15:10.913
Modified: 2024-11-21T08:13:41.243
Link: CVE-2023-38493
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA