CVE-2018-1000850

NONE EPSS 89.3%
Published Dec 20, 20187y ago · Modified Jun 17, 20262w ago
Find Similar
Published Dec 20, 2018 7y ago
Last Modified Jun 17, 2026 2w ago

Description

Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder class, method addPathParameter that can result in By manipulating the URL an attacker could add or delete resources otherwise unavailable to her.. This attack appear to be exploitable via An attacker should have access to an encoded path parameter on POST, PUT or DELETE request.. This vulnerability appears to have been fixed in 2.5.0 and later.

Threat Intelligence

EPSS Exploit Probability
89.3% percentile
Exploit & Patch Status
Public Exploit Known
Patch Available

Weaknesses 1

CWE-22 Path Traversal Resource Mgmt

Affected Products 1

VendorProductVersionRange
squareupretrofit*≥2.0.0  –  <2.5.0

References 7

  • access.redhat.com https://access.redhat.com/errata/RHSA-2019:3892
  • github.com https://github.com/square/retrofit/blob/master/CHANGELOG.md
    Release NotesThird Party Advisory
  • github.com https://github.com/square/retrofit/commit/b9a7f6ad72073ddd40254c0058710e87a073047d#diff-943ec7ed35e68201824904d1dc0ec982
    PatchThird Party Advisory
  • ihacktoprotect.com https://ihacktoprotect.com/post/retrofit-path-traversal/
    ExploitThird Party Advisory
  • lists.apache.org https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f%40%3Cdev.drill.apache.org%3E
  • lists.apache.org https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442%40%3Cdev.drill.apache.org%3E
  • lists.apache.org https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc%40%3Cissues.drill.apache.org%3E

Remediation

  • github.com https://github.com/square/retrofit/commit/b9a7f6ad72073ddd40254c0058710e87a073047d#diff-943ec7ed35e68201824904d1dc0ec982
    PatchThird Party Advisory