Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-38819

Опубликовано: 19 дек. 2024
Источник: nvd
CVSS3: 7.5
EPSS Высокий

Описание

Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.

EPSS

Процентиль: 99%
0.71765
Высокий

7.5 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 года назад

Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.

CVSS3: 7.5
redhat
больше 1 года назад

Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.

CVSS3: 7.5
debian
около 1 года назад

Applications serving static resources through the functional web frame ...

CVSS3: 7.5
github
около 1 года назад

Spring Framework Path Traversal vulnerability

CVSS3: 7.5
fstec
больше 1 года назад

Уязвимость функциональных веб-фреймворков WebMvc.fn и WebFlux.f программной платформы Spring Framework, позволяющая нарушителю получить доступ к произвольному файлу в файловой системе

EPSS

Процентиль: 99%
0.71765
Высокий

7.5 High

CVSS3

Дефекты

CWE-22