Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-76qr-mmh8-cp8f

Опубликовано: 19 окт. 2018
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Moderate severity vulnerability that affects com.sparkjava:spark-core

In Spark before 2.7.2, a remote attacker can read unintended static files via various representations of absolute or relative pathnames, as demonstrated by file: URLs and directory traversal sequences. NOTE: this product is unrelated to Ignite Realtime Spark.

Пакеты

Наименование

com.sparkjava:spark-core

maven
Затронутые версииВерсия исправления

< 2.7.2

2.7.2

EPSS

Процентиль: 58%
0.00372
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.3
redhat
почти 8 лет назад

In Spark before 2.7.2, a remote attacker can read unintended static files via various representations of absolute or relative pathnames, as demonstrated by file: URLs and directory traversal sequences. NOTE: this product is unrelated to Ignite Realtime Spark.

CVSS3: 5.3
nvd
почти 8 лет назад

In Spark before 2.7.2, a remote attacker can read unintended static files via various representations of absolute or relative pathnames, as demonstrated by file: URLs and directory traversal sequences. NOTE: this product is unrelated to Ignite Realtime Spark.

EPSS

Процентиль: 58%
0.00372
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-22