HIGHMaven →
Paths contain matrix variables bypass decorators
Paths contain matrix variables bypass decorators
Affected packages
- com.linecorp.armeria:armeria— before 1.24.3
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/line/armeria/security/advisories/GHSA-wvp2-9ppw-337j
- https://nvd.nist.gov/vuln/detail/CVE-2023-38493
- https://github.com/line/armeria/commit/039db50bbfc88014ea8737fd1e1ddd6fd3fc4f07
- https://github.com/line/armeria/commit/49e04ef231ad65750739529c7fa4ce946ff7588b
- https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-controller/ann-methods/matrix-variables.html
- https://github.com/line/armeria
Structured record: https://osv.dev/vulnerability/GHSA-wvp2-9ppw-337j
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta