Lack of data validation - Path Traversal In org.springframework:spring-webflux
Description
Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources.
Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 11 | - | ||
debian 12 | - | ||
debian 13 | - | ||
debian 14 | - | ||
rpm rhel8 | - | - | |
rpm rhel9 | - | - | |
rpm rhel8 | - | - | |
maven | 7.0.8, 6.2.19 | ||
maven | 7.0.8, 6.2.19 |
Aliases
1. 2. 3. 4. 5. 6.
References
1. 2. 3.