Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-9878

Опубликовано: 21 дек. 2016
Источник: redhat
CVSS3: 5.6
CVSS2: 6.8

Описание

An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.

It was found that ResourceServlet in Spring Framework does not sanitize the paths that have been provided properly. An attacker can utilize this flaw to conduct a directory traversal attacks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat BPM Suite 6springframeworkNot affected
Red Hat Enterprise Virtualization 3jasperreports-server-proUnder investigation
Red Hat JBoss A-MQ 6karafAffected
Red Hat JBoss BRMS 6springframeworkNot affected
Red Hat JBoss Data Virtualization 6springframeworkNot affected
Red Hat JBoss Enterprise Application Platform 5spring-webmvcWill not fix
Red Hat JBoss Fuse 6karafAffected
Red Hat Mobile Application Platform 4millicoreNot affected
Red Hat OpenShift Enterprise 2activemqNot affected
Red Hat OpenShift Enterprise 2cartridge-amqAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=1408164Framework: Directory Traversal in the Spring Framework ResourceServlet

5.6 Medium

CVSS3

6.8 Medium

CVSS2

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 8 лет назад

An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.

CVSS3: 7.5
nvd
больше 8 лет назад

An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.

CVSS3: 7.5
debian
больше 8 лет назад

An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2 ...

CVSS3: 7.5
github
больше 6 лет назад

Pivotal Spring Framework Paths provided to the ResourceServlet were not properly sanitized

5.6 Medium

CVSS3

6.8 Medium

CVSS2