{"id":"GHSA-cjx7-399x-p2rj","summary":"Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in micronaut-core","details":"With a basic configuration like\n\n```yaml\nrouter:\n  static-resources:\n    assets:\n      enabled: true\n      mapping: /.assets/public/**\n      paths: file:/home/lstrmiska/test/\n```\n\nit is possible to access any file from a filesystem, using \"/../../\" in URL, as Micronaut does not restrict file access to configured paths. \n\n**Repro Steps**\n- create a file test.txt in /home/lstrmiska\n- start micronaut\n- execute command\n`curl -v --path-as-is \"http://localhost:8080/.assets/public/../test.txt\"`\n\n\n### Impact\n\nMicronaut can potentially leak sensitive information.\n\nSee https://cwe.mitre.org/data/definitions/22.html\n\n### Patches\n\n```\ndiff --git a/core/src/main/java/io/micronaut/core/io/file/DefaultFileSystemResourceLoader.java b/core/src/main/java/io/micronaut/core/io/file/DefaultFileSystemResourceLoader.java\nindex 2f5a91403..19d3b7f05 100644\n--- a/core/src/main/java/io/micronaut/core/io/file/DefaultFileSystemResourceLoader.java\n+++ b/core/src/main/java/io/micronaut/core/io/file/DefaultFileSystemResourceLoader.java\n@@ -69,6 +69,9 @@ public class DefaultFileSystemResourceLoader implements FileSystemResourceLoader\n     @Override\n     public Optional\u003cInputStream\u003e getResourceAsStream(String path) {\n         Path filePath = getFilePath(normalize(path));\n+        if (pathOutsideBase(filePath)) {\n+            return Optional.empty();\n+        }\n         try {\n             return Optional.of(Files.newInputStream(filePath));\n         } catch (IOException e) {\n@@ -79,7 +82,7 @@ public class DefaultFileSystemResourceLoader implements FileSystemResourceLoader\n     @Override\n     public Optional\u003cURL\u003e getResource(String path) {\n         Path filePath = getFilePath(normalize(path));\n-        if (Files.exists(filePath) && Files.isReadable(filePath) && !Files.isDirectory(filePath)) {\n+        if (!pathOutsideBase(filePath) && Files.exists(filePath) && Files.isReadable(filePath) && !Files.isDirectory(filePath)) {\n             try {\n                 URL url = filePath.toUri().toURL();\n                 return Optional.of(url);\n@@ -117,4 +120,15 @@ public class DefaultFileSystemResourceLoader implements FileSystemResourceLoader\n     private Path getFilePath(String path) {\n         return baseDirPath.map(dir -\u003e dir.resolve(path)).orElseGet(() -\u003e Paths.get(path));\n     }\n+\n+    private boolean pathOutsideBase(Path path) {\n+        if (baseDirPath.isPresent()) {\n+            Path baseDir = baseDirPath.get();\n+            if (path.isAbsolute() == baseDir.isAbsolute()) {\n+                Path relativePath = baseDir.relativize(path);\n+                return relativePath.startsWith(\"..\");\n+            }\n+        }\n+        return false;\n+    }\n }\n-- \n\n```\n\n### Workarounds\n\n- do not use ** in mapping, use only * which exposes only flat structure of a directory not allowing traversal\n- run micronaut in chroot (linux only)\n\n### References\n\nSee https://cwe.mitre.org/data/definitions/22.html\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [Github](https://github.com/micronaut-projects/micronaut-core/issues)\n* Email us at [info@micronaut.io](mailto:info@micronaut.io)\n","aliases":["CVE-2021-32769"],"modified":"2026-05-07T05:00:31.945063545Z","published":"2021-07-26T21:15:08Z","database_specific":{"github_reviewed_at":"2021-07-22T20:25:11Z","nvd_published_at":"2021-07-16T19:15:00Z","cwe_ids":["CWE-22"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/micronaut-projects/micronaut-core/security/advisories/GHSA-cjx7-399x-p2rj"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-32769"},{"type":"WEB","url":"https://github.com/micronaut-projects/micronaut-core/commit/a0cfeb13bf1ef5d692d16d4a3b91b34b7456bb11"}],"affected":[{"package":{"name":"io.micronaut:micronaut-http-server-netty","ecosystem":"Maven","purl":"pkg:maven/io.micronaut/micronaut-http-server-netty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.9"}]}],"versions":["1.0.0","1.0.0.RC3","1.0.1","1.0.2","1.0.3","1.0.4","1.0.5","1.1.0","1.1.0.M1","1.1.0.M2","1.1.0.RC1","1.1.0.RC2","1.1.1","1.1.2","1.1.3","1.1.4","1.2.0","1.2.0.RC1","1.2.0.RC2","1.2.1","1.2.10","1.2.11","1.2.2","1.2.3","1.2.4","1.2.5","1.2.6","1.2.7","1.2.8","1.2.9","1.3.0","1.3.0.M1","1.3.0.M2","1.3.0.RC1","1.3.1","1.3.2","1.3.3","1.3.4","1.3.5","1.3.6","1.3.7","2.0.0","2.0.0.M1","2.0.0.M2","2.0.0.M3","2.0.0.RC1","2.0.0.RC2","2.0.1","2.0.2","2.0.3","2.1.0","2.1.1","2.1.2","2.1.3","2.1.4","2.2.0","2.2.1","2.2.2","2.2.3","2.3.0","2.3.1","2.3.2","2.3.3","2.3.4","2.4.0","2.4.1","2.4.2","2.4.3","2.4.4","2.5.0","2.5.1","2.5.2","2.5.3","2.5.4","2.5.5","2.5.6","2.5.7","2.5.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/07/GHSA-cjx7-399x-p2rj/GHSA-cjx7-399x-p2rj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}