7.5
CVSSv3

CVE-2018-1000850

Published: 20/12/2018 Updated: 07/11/2023
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:P

Vulnerability Summary

Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder class, method addPathParameter that can result in By manipulating the URL an attacker could add or delete resources otherwise unavailable to her.. This attack appear to be exploitable via An attacker should have access to an encoded path parameter on POST, PUT or DELETE request.. This vulnerability appears to have been fixed in 2.5.0 and later.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

squareup retrofit

Vendor Advisories

Synopsis Important: Red Hat Fuse 750 security update Type/Severity Security Advisory: Important Topic A minor version update (from 74 to 75) is now available for Red Hat Fuse The purpose of this text-only errata is to inform you about the security issues fixed in this releaseRed Hat Product Security h ...

Github Repositories

apkLibDetect 工具链由两部分组成: 前端为LibScout - githubcom/reddr/LibScout 后端为从snyk采集的数据库 - snykio/vuln Run 需先build LibScout Generate a runnable jar with the gradle wrapper gradlew (Linux/MacOS) or gradlewbat (Windows), by invoking it with the build task, eg /gradlew build The LibScoutjar is output to the build/lib