CVE-2025-1584 Details
Description
A vulnerability classified as problematic was found in opensolon Solon up to 3.0.8. This vulnerability affects unknown code of the file solon-projects/solon-web/solon-web-staticfiles/src/main/java/org/noear/solon/web/staticfiles/StaticMappings.java. The manipulation leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.0.9 is able to address this issue. The name of the patch is f46e47fd1f8455b9467d7ead3cdb0509115b2ef1. It is recommended to upgrade the affected component.
A path traversal vulnerability has been identified in OpenSolon Solon versions through 3.0.8. The issue resides in the static file management component, specifically within the StaticMappings.java file. This vulnerability allows remote attackers to manipulate file paths using '../' sequences, potentially leading to unauthorized file access. The problem has been publicly disclosed and exploited.
Users are advised to upgrade to OpenSolon Solon version 3.0.9 or later, where this vulnerability has been addressed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 23, 2025CISA-ADP
Assessed Feb 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/opensolon/solon/commit/f46e47fd1f8455b9467d7ead3cdb0509115b2ef1 | [email protected] | Source CodeVendor |
| https://github.com/opensolon/solon/issues/332 | [email protected] | ExploitIssue TrackingRemedyVendor |
| https://github.com/opensolon/solon/issues/332#issue-2866229828 | [email protected] | Issue TrackingVendor |
| https://github.com/opensolon/solon/issues/332#issuecomment-2674330700 | [email protected] | Issue TrackingVendor |
| https://vuldb.com/?ctiid.296560 | [email protected] | AdvisoryContent Wall |
| https://vuldb.com/?id.296560 | [email protected] | AdvisoryContent Wall |
| https://vuldb.com/?submit.504454 | [email protected] | Issue TrackingPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-23 | Relative Path Traversal | [email protected] |
| CWE-24 | Path Traversal: '../filedir' | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| opensolon Solon | <= 3.0.8 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 23, 2025 | New CVE Received | [email protected] |
Volerion