Lucene search

K
osvGoogleOSV:GHSA-V4MQ-P756-P4F5
HistoryMay 13, 2022 - 1:30 a.m.

Play Framework's Assets controller vulnerable to directory traversal

2022-05-1301:30:27
Google
osv.dev
8
play framework
assets controller
directory traversal
vulnerability
windows
remote attacker
http requests

EPSS

0.021

Percentile

89.3%

A directory traversal vulnerability has been found in the Assets controller in Play Framework 2.6.12 through 2.6.15 (fixed in 2.6.16) when running on Windows. It allows a remote attacker to download arbitrary files from the target server via specially crafted HTTP requests.

EPSS

0.021

Percentile

89.3%

Related for OSV:GHSA-V4MQ-P756-P4F5