Lack of data validation - Path Traversal In log4j
Description
Spring Framework Improper Path Limitation with Script View Templates Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
rpm rhel8 | - | - | |
debian 11 | - | ||
rpm rhel9 | - | - | |
maven | 7.0.6, 6.2.17 | ||
maven | 7.0.6, 6.2.17 | ||
rpm rhel9 | - | - | |
rpm rhel8 | - | - | |
debian 12 | - | ||
debian 13 | - | ||
debian 14 | - |
Aliases
1. 2. 3. 4. 5. 6.
References
1.