Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2m8h-fgr8-2q9w

Опубликовано: 04 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Pivotal Spring Framework Paths provided to the ResourceServlet were not properly sanitized

An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.

Пакеты

Наименование

org.springframework:spring-webmvc

maven
Затронутые версииВерсия исправления

< 3.2.18

3.2.18

Наименование

org.springframework:spring-webmvc

maven
Затронутые версииВерсия исправления

>= 4.2.0, < 4.2.9

4.2.9

Наименование

org.springframework:spring-webmvc

maven
Затронутые версииВерсия исправления

>= 4.3.0, < 4.3.5

4.3.5

EPSS

Процентиль: 89%
0.04927
Низкий

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.

CVSS3: 5.6
redhat
больше 8 лет назад

An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.

CVSS3: 7.5
nvd
больше 8 лет назад

An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.

CVSS3: 7.5
debian
больше 8 лет назад

An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2 ...

EPSS

Процентиль: 89%
0.04927
Низкий

7.5 High

CVSS3

Дефекты

CWE-22