Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-9878

Опубликовано: 29 дек. 2016
Источник: debian
EPSS Низкий

Описание

An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
libspring-javafixed4.3.5-1package
libspring-javano-dsawheezypackage

Примечания

  • https://pivotal.io/security/cve-2016-9878

  • Fixed by: https://github.com/spring-projects/spring-framework/commit/e2d6e709c3c65a4951eb096843ee75d5200cfcad (4.3.x branch)

  • Fixed by: https://github.com/spring-projects/spring-framework/commit/43bf008fbcd0d7945e2fcd5e30039bc4d74c7a98 (4.2.x branch)

  • Fixed by: https://github.com/spring-projects/spring-framework/commit/a7dc48534ea501525f11369d369178a60c2f47d0 (3.2.x branch)

  • https://jira.spring.io/browse/SPR-14946

EPSS

Процентиль: 89%
0.04927
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.

CVSS3: 5.6
redhat
больше 8 лет назад

An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.

CVSS3: 7.5
nvd
больше 8 лет назад

An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.

CVSS3: 7.5
github
больше 6 лет назад

Pivotal Spring Framework Paths provided to the ResourceServlet were not properly sanitized

EPSS

Процентиль: 89%
0.04927
Низкий