Описание
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a request using a specially crafted URL that can lead a directory traversal attack.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
Red Hat Enterprise Linux 8 | springframework | Not affected | ||
Red Hat JBoss A-MQ 6 | spring | Out of support scope | ||
Red Hat JBoss BRMS 5 | spring | Out of support scope | ||
Red Hat JBoss Data Virtualization 6 | spring | Out of support scope | ||
Red Hat JBoss Enterprise Application Platform 5 | spring | Out of support scope | ||
Red Hat JBoss Fuse 6 | spring | Will not fix | ||
Red Hat JBoss Fuse Integration Service 2 | spring | Affected | ||
Red Hat JBoss Fuse Service Works 6 | spring | Out of support scope | ||
Red Hat JBoss SOA Platform 5 | spring | Out of support scope | ||
Red Hat Mobile Application Platform 4 | spring | Not affected |
Показывать по
Дополнительная информация
Статус:
6.5 Medium
CVSS3
Связанные уязвимости
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a request using a specially crafted URL that can lead a directory traversal attack.
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a request using a specially crafted URL that can lead a directory traversal attack.
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior t ...
Path Traversal in org.springframework:spring-core
6.5 Medium
CVSS3