Home

Description

In Eclipse Vert.x versions [4.0.0, 4.5.21] and [5.0.0, 5.0.4], a StaticHandler configuration for restricting access to hidden files fails to restrict access to hidden directories, allowing unauthorized users to retrieve files within them (e.g. '.git/config').

PUBLISHED Reserved 2025-10-20 | Published 2025-10-22 | Updated 2025-10-22 | Assigner eclipse




MEDIUM: 6.3CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-552 Files or Directories Accessible to External Parties

Product status

Default status
unaffected

4.0.0 (maven) before 4.5.22
affected

5.0.0 (maven) before 5.0.5
affected

Credits

Sho Odagiri finder

References

gitlab.eclipse.org/...ity/vulnerability-reports/-/issues/304

cve.org (CVE-2025-11965)

nvd.nist.gov (CVE-2025-11965)

Download JSON