Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-38819

Опубликовано: 17 окт. 2024
Источник: redhat
CVSS3: 7.5
EPSS Высокий

Описание

Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.

A flaw was found in the Spring Framework. Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. This flaw allows an attacker to craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.

Отчет

This vulnerability is of important severity because it enables path traversal attacks that allow unauthorized access to arbitrary files on the server. Exploiting this flaw could expose sensitive information such as application configuration files, authentication credentials, or environment secrets, potentially compromising the entire system. Moreover, if the application process has elevated privileges, an attacker could access system files or even gain further control over the server.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2org.springframework/spring-webmvcNot affected
Red Hat AMQ Broker 7org.springframework/spring-webmvcWill not fix
Red Hat build of Apache Camel - HawtIO 4org.springframework/spring-webmvcNot affected
Red Hat Build of Keycloakorg.springframework/spring-webmvcWill not fix
Red Hat build of OptaPlanner 8org.springframework/spring-webmvcAffected
Red Hat Data Grid 8org.springframework/spring-webmvcAffected
Red Hat Fuse 7org.springframework/spring-webmvcWill not fix
Red Hat Integration Camel K 1org.springframework/spring-webmvcWill not fix
Red Hat JBoss Data Grid 7org.springframework/spring-webmvcNot affected
Red Hat JBoss Enterprise Application Platform 7spring-webmvcNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2327614org.springframework:spring-webmvc: Path traversal vulnerability in functional web frameworks

EPSS

Процентиль: 99%
0.71765
Высокий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 года назад

Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.

CVSS3: 7.5
nvd
около 1 года назад

Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.

CVSS3: 7.5
debian
около 1 года назад

Applications serving static resources through the functional web frame ...

CVSS3: 7.5
github
около 1 года назад

Spring Framework Path Traversal vulnerability

CVSS3: 7.5
fstec
больше 1 года назад

Уязвимость функциональных веб-фреймворков WebMvc.fn и WebFlux.f программной платформы Spring Framework, позволяющая нарушителю получить доступ к произвольному файлу в файловой системе

EPSS

Процентиль: 99%
0.71765
Высокий

7.5 High

CVSS3