Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-38819

Опубликовано: 17 окт. 2024
Источник: redhat
CVSS3: 7.5
EPSS Средний

Описание

Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.

A flaw was found in the Spring Framework. Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. This flaw allows an attacker to craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.

Отчет

This vulnerability is of important severity because it enables path traversal attacks that allow unauthorized access to arbitrary files on the server. Exploiting this flaw could expose sensitive information such as application configuration files, authentication credentials, or environment secrets, potentially compromising the entire system. Moreover, if the application process has elevated privileges, an attacker could access system files or even gain further control over the server.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2spring-webmvcNot affected
Red Hat AMQ Broker 7spring-webmvcWill not fix
Red Hat build of Apache Camel - HawtIO 4spring-webmvcNot affected
Red Hat Build of Keycloakspring-webmvcWill not fix
Red Hat build of OptaPlanner 8spring-webmvcWill not fix
Red Hat Data Grid 8spring-webmvcAffected
Red Hat Fuse 7spring-webmvcWill not fix
Red Hat Integration Camel K 1spring-webmvcAffected
Red Hat JBoss Data Grid 7spring-webmvcNot affected
Red Hat JBoss Enterprise Application Platform 7spring-webmvcNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2327614org.springframework:spring-webmvc: Path traversal vulnerability in functional web frameworks

EPSS

Процентиль: 99%
0.54862
Средний

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.

CVSS3: 7.5
nvd
больше 1 года назад

Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.

CVSS3: 7.5
debian
больше 1 года назад

Applications serving static resources through the functional web frame ...

CVSS3: 7.5
github
больше 1 года назад

Spring Framework Path Traversal vulnerability

CVSS3: 7.5
fstec
почти 2 года назад

Уязвимость функциональных веб-фреймворков WebMvc.fn и WebFlux.f программной платформы Spring Framework, позволяющая нарушителю получить доступ к произвольному файлу в файловой системе

EPSS

Процентиль: 99%
0.54862
Средний

7.5 High

CVSS3