CVE-2018-1000850

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-1000850
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1000850.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2018-1000850
Aliases
Published
2018-12-20T15:29:02Z
Modified
2024-05-30T01:22:28.485808Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder class, method addPathParameter that can result in By manipulating the URL an attacker could add or delete resources otherwise unavailable to her.. This attack appear to be exploitable via An attacker should have access to an encoded path parameter on POST, PUT or DELETE request.. This vulnerability appears to have been fixed in 2.5.0 and later.

References

Affected packages

Git / github.com/square/retrofit

Affected ranges

Type
GIT
Repo
https://github.com/square/retrofit
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

0.*

0.6.0-rc1
0.6.0-rc2
0.6.0-rc3
0.6.0-rc4
0.6.0-rc5
0.6.0-rc6

parent-1.*

parent-1.0.0
parent-1.0.1
parent-1.0.2
parent-1.1.0
parent-1.1.1
parent-1.2.0
parent-1.2.1
parent-1.2.2
parent-1.3.0
parent-1.4.0
parent-1.4.1
parent-1.5.0
parent-1.5.1
parent-1.6.0
parent-1.6.1
parent-1.7.0

parent-2.*

parent-2.0.0
parent-2.0.0-beta1
parent-2.0.0-beta2
parent-2.0.0-beta3
parent-2.0.0-beta4
parent-2.0.1
parent-2.0.2
parent-2.1.0
parent-2.2.0
parent-2.3.0
parent-2.4.0