Path Traversal
The Asset Pipeline Grails Plugin contains an Incorrect Access Control vulnerability in Applications deployed in Jetty that can result in arbitrary file downloads.
The Asset Pipeline Grails Plugin contains an Incorrect Access Control vulnerability in Applications deployed in Jetty that can result in arbitrary file downloads.
An issue was discovered in the Asset Pipeline plugin for Grails. An attacker can perform directory traversal via a crafted request when a servlet-based application is executed in Jetty, because there is a classloader vulnerability that can allow a reverse file traversal route in AssetPipelineFilter.groovy or AssetPipelineFilterCore.groovy.