Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-3625

Опубликовано: 11 нояб. 2014
Источник: redhat
CVSS2: 5
EPSS Средний

Описание

Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.

A directory traversal flaw was found in the way the Spring Framework sanitized certain URLs. A remote attacker could use this flaw to obtain any file on the file system that was also accessible to the process in which the Spring web application was running.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss BRMS 5springWill not fix
Red Hat JBoss Enterprise Web Server 1amq-6.1Affected
Red Hat JBoss Enterprise Web Server 1fuse-6.1Affected
Red Hat JBoss Portal 5springWill not fix
Red Hat JBoss Portal 6springAffected
Red Hat JBoss A-MQ 6.1FixedRHSA-2015:023618.02.2015
Red Hat JBoss BPMS 6.0springFixedRHSA-2015:023417.02.2015
Red Hat JBoss BRMS 6.0springFixedRHSA-2015:023517.02.2015
Red Hat JBoss Fuse 6.1FixedRHSA-2015:023618.02.2015
Red Hat JBoss Fuse Service Works 6.0springFixedRHSA-2015:072024.03.2015

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1165936Framework: directory traversal flaw

EPSS

Процентиль: 96%
0.29247
Средний

5 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.

nvd
больше 10 лет назад

Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.

debian
больше 10 лет назад

Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 th ...

github
около 3 лет назад

Improper Limitation of a Pathname to a Restricted Directory in Spring Framework

EPSS

Процентиль: 96%
0.29247
Средний

5 Medium

CVSS2