Description
An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1853-1 | libspring-java security update |
EUVD |
EUVD-2018-0477 | An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks. |
Github GHSA |
GHSA-2m8h-fgr8-2q9w | Pivotal Spring Framework Paths provided to the ResourceServlet were not properly sanitized |
Ubuntu USN |
USN-4774-1 | Spring Framework vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-08-06T03:07:30.827Z
Reserved: 2016-12-06T00:00:00.000Z
Link: CVE-2016-9878
No data.
Status : Modified
Published: 2016-12-29T09:59:00.820
Modified: 2026-05-06T22:30:45.220
Link: CVE-2016-9878
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA
Ubuntu USN