Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-38819

Опубликовано: 19 дек. 2024
Источник: nvd
CVSS3: 7.5
EPSS Средний

Описание

Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.

EPSS

Процентиль: 99%
0.54862
Средний

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.

CVSS3: 7.5
redhat
почти 2 года назад

Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.

CVSS3: 7.5
debian
больше 1 года назад

Applications serving static resources through the functional web frame ...

CVSS3: 7.5
github
больше 1 года назад

Spring Framework Path Traversal vulnerability

CVSS3: 7.5
fstec
почти 2 года назад

Уязвимость функциональных веб-фреймворков WebMvc.fn и WebFlux.f программной платформы Spring Framework, позволяющая нарушителю получить доступ к произвольному файлу в файловой системе

EPSS

Процентиль: 99%
0.54862
Средний

7.5 High

CVSS3

Дефекты

CWE-22