CVE-2021-43795
Estado: ModificadaAlta (7.5)—
Armeria is an open source microservice framework. In affected versions an attacker can access an Armeria server's local file system beyond its restricted directory by sending an HTTP request whose path contains `%2F` (encoded `/`), such as `/files/..%2Fsecrets.txt`, bypassing Armeria's path validation logic. Armeria 1.13.4 or above contains the hardened path validation logic that handles `%2F` properly. This vulnerability can be worked around by inserting a decorator that performs an additional validation on the request path.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.69%
- Percentil entre todas las CVEs puntuadas: 76
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-22
Referencias
- https://github.com/line/armeria/commit/e2697a575e9df6692b423e02d731f293c1313284
- https://github.com/line/armeria/pull/3855
- https://github.com/line/armeria/security/advisories/GHSA-8fp4-rp6c-5gcv
- https://github.com/line/armeria/commit/e2697a575e9df6692b423e02d731f293c1313284
- https://github.com/line/armeria/pull/3855
- https://github.com/line/armeria/security/advisories/GHSA-8fp4-rp6c-5gcv
JSON original (NVD)
Mostrar
{
"id": "CVE-2021-43795",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security-advisories@github.com",
"affectedData": [
{
"vendor": "line",
"product": "armeria",
"versions": [
{
"status": "affected",
"version": "< 1.13.4"
}
]
}
]
}
],
"published": "2021-12-02T18:15:08.267",
"references": [
{
"url": "https://github.com/line/armeria/commit/e2697a575e9df6692b423e02d731f293c1313284",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/line/armeria/pull/3855",
"tags": [
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/line/armeria/security/advisories/GHSA-8fp4-rp6c-5gcv",
"tags": [
"Third Party Advisory"
],
"source": "security-advisories@github.com"
},
{
"url": "https://github.com/line/armeria/commit/e2697a575e9df6692b423e02d731f293c1313284",
"tags": [
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/line/armeria/pull/3855",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/line/armeria/security/advisories/GHSA-8fp4-rp6c-5gcv",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "security-advisories@github.com",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Armeria is an open source microservice framework. In affected versions an attacker can access an Armeria server's local file system beyond its restricted directory by sending an HTTP request whose path contains `%2F` (encoded `/`), such as `/files/..%2Fsecrets.txt`, bypassing Armeria's path validation logic. Armeria 1.13.4 or above contains the hardened path validation logic that handles `%2F` properly. This vulnerability can be worked around by inserting a decorator that performs an additional validation on the request path."
},
{
"lang": "es",
"value": "Armeria es un framework de microservicios de código abierto. En las versiones afectadas, un atacante puede acceder al sistema de archivos local de un servidor de Armeria más allá de su directorio restringido mediante el envío de una petición HTTP cuya ruta contenga \"%2F\" (codificado \"/\"), como \"/files/..%2Fsecrets.txt\", omitiendo la lógica de comprobación de rutas de Armeria. Armeria versión 1.13.4 o superior, contiene una lógica de comprobación de rutas reforzada que maneja \"%2F\" apropiadamente. Esta vulnerabilidad puede solucionarse al insertar un decorador que lleve a cabo una comprobación adicional en la ruta de petición"
}
],
"lastModified": "2026-06-17T04:11:27.303",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:linecorp:armeria:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1C4CC5EF-C8FD-41AB-A2C6-DA8D6E3ED2B6",
"versionEndExcluding": "1.13.4"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-advisories@github.com"
}