GHSA-p4q6-qxjx-8jgp
HIGHCVE-2021-21234The nature of this library is to expose a log file directory via admin (spring boot actuator) HTTP endpoints. Both the filename to view and a base folder (relative to the logging folder root) can be specified via request parameters. While the filename parameter was checked to prevent directory traversal exploits (so that filename=../somefile would not work), the base folder parameter was not suffi
- Affected
- < 0.2.13
- Fixed in
- 0.2.13
- Weakness
- CWE-22
- Published
- 2021-01-05
- Source
- github