Lack of data validation - Path Traversal In org.springframework:spring-webmvc
Description
Improper Limitation of a Pathname to a Restricted Directory in Spring Framework Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
maven | 3.2.12, 4.0.8, 4.1.2 | ||
debian 14 | 3.2.13-1 | ||
debian 11 | 3.2.13-1 | ||
debian 13 | 3.2.13-1 | ||
debian 12 | 3.2.13-1 |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3. 4. 5. 6. 7. 8. 9.