SCA: security update for com.squareup.retrofit2:retrofit (GHSA-8p8g-f9vg-r7xr)

high Tenable Cloud Security Plugin ID 422024

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal
vulnerability in RequestBuilder class, method addPathParameter that can result in By manipulating the URL
an attacker could add or delete resources otherwise unavailable to her.. This attack appear to be
exploitable via An attacker should have access to an encoded path parameter on POST, PUT or DELETE
request.. This vulnerability appears to have been fixed in 2.5.0 and later. (CVE-2018-1000850)

See Also

https://github.com/advisories/GHSA-8p8g-f9vg-r7xr

Plugin Details

Severity: High

ID: 422024

Version: Revision 1.3

Type: Local

Family: SCA Checks

Published: 3/28/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:P

CVSS Score Source: CVE-2018-1000850

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 12/21/2018

Vulnerability Publication Date: 12/20/2018

Reference Information

CVE: CVE-2018-1000850

cwe: CWE-22