CVE-2014-3578
published 2015-02-19CVE-2014-3578: Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a…
PriorityP335medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
6.21%
92.7th percentile
Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libspring-java | < libspring-java 3.2.13-1 (bookworm) | libspring-java 3.2.13-1 (bookworm) |
| pivotal_software | spring_framework | >= 3.2.0 < 3.2.9 | 3.2.9 |
| pivotal_software | spring_framework | >= 4.0.0 < 4.0.5 | 4.0.5 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Limitation of a Pathname to a Restricted Directory in Spring Framework
osv·2022-05-14
CVE-2014-3578 [MEDIUM] Improper Limitation of a Pathname to a Restricted Directory in Spring Framework
Improper Limitation of a Pathname to a Restricted Directory in Spring Framework
Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.
GHSA
Improper Limitation of a Pathname to a Restricted Directory in Spring Framework
ghsa·2022-05-14
CVE-2014-3578 [MEDIUM] CWE-22 Improper Limitation of a Pathname to a Restricted Directory in Spring Framework
Improper Limitation of a Pathname to a Restricted Directory in Spring Framework
Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.
OSV
libspring-java vulnerabilities
osv·2021-03-17·CVSS 8.8
CVE-2015-3192 [HIGH] libspring-java vulnerabilities
libspring-java vulnerabilities
Toshiaki Maki discovered that Spring Framework incorrectly handled certain
XML files. A remote attacker could exploit this with a crafted XML file to
cause a denial of service. (CVE-2015-3192)
Alvaro Muñoz discovered that Spring Framework incorrectly handled certain
URLs. A remote attacker could possibly use this issue to cause a reflected
file download. (CVE-2015-5211)
It was discovered that Spring Framework did not properly sanitize path
inputs. An attacker could possibly use this issue to read arbitrary files,
resulting in a directory traversal attack (CVE-2016-9878)
It was discovered that Spring Framework incorrectly handled XML documents.
An attacker could possibly use this issue to generate an XML external
entity attack, resulting in a denial of ser
OSV
CVE-2014-3578: Directory traversal vulnerability in Pivotal Spring Framework 3
osv·2015-02-19·CVSS 5.0
CVE-2014-3578 [MEDIUM] CVE-2014-3578: Directory traversal vulnerability in Pivotal Spring Framework 3
Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.
Ubuntu
Spring Framework vulnerabilities
vendor_ubuntu·2021-03-17·CVSS 8.8
CVE-2015-5211 [HIGH] Spring Framework vulnerabilities
Title: Spring Framework vulnerabilities
Summary: Several security issues were fixed in Spring Framework.
Toshiaki Maki discovered that Spring Framework incorrectly handled certain
XML files. A remote attacker could exploit this with a crafted XML file to
cause a denial of service. (CVE-2015-3192)
Alvaro Muñoz discovered that Spring Framework incorrectly handled certain
URLs. A remote attacker could possibly use this issue to cause a reflected
file download. (CVE-2015-5211)
It was discovered that Spring Framework did not properly sanitize path
inputs. An attacker could possibly use this issue to read arbitrary files,
resulting in a directory traversal attack (CVE-2016-9878)
It was discovered that Spring Framework incorrectly handled XML documents.
An attacker could possibly use this is
Red Hat
Framework: Directory traversal
vendor_redhat·2014-09-05·CVSS 5.0
CVE-2014-3578 [MEDIUM] CWE-22 Framework: Directory traversal
Framework: Directory traversal
Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.
A directory traversal flaw was found in the Spring Framework. A remote attacker could use this flaw to access arbitrary files on a server, and bypassing security restrictions that are otherwise in place.
Package: spring (Red Hat JBoss BRMS 5) - Will not fix
Package: spring (Red Hat JBoss Data Virtualization 6) - Not affected
Package: spring (Red Hat JBoss Portal 5) - Will not fix
Package: spring (Red Hat JBoss Portal 6) - Affected
Debian
CVE-2014-3578: libspring-java - Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 a...
vendor_debian·2014·CVSS 5.0
CVE-2014-3578 [MEDIUM] CVE-2014-3578: libspring-java - Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 a...
Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.
Scope: local
bookworm: resolved (fixed in 3.2.13-1)
bullseye: resolved (fixed in 3.2.13-1)
forky: resolved (fixed in 3.2.13-1)
sid: resolved (fixed in 3.2.13-1)
trixie: resolved (fixed in 3.2.13-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3578 springframework: Spring Framework: Directory traversal [fedora-all]
bugzilla·2014-09-06·CVSS 5.0
CVE-2014-3578 [MEDIUM] CVE-2014-3578 springframework: Spring Framework: Directory traversal [fedora-all]
CVE-2014-3578 springframework: Spring Framework: Directory traversal [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2014-3578 Spring Framework: Directory traversal
bugzilla·2014-08-20·CVSS 5.0
CVE-2014-3578 [MEDIUM] CVE-2014-3578 Spring Framework: Directory traversal
CVE-2014-3578 Spring Framework: Directory traversal
It was discovered that Spring Framework contained an undisclosed directory traversal vulnerability. A remote attacker could use this flaw to access arbitrary files on a server bypassing security restrictions that are otherwise in place.
References:
http://jvndb.jvn.jp/en/contents/2014/JVNDB-2014-000054.html
Discussion:
This is now public. According to the upstream report, this is fixed in 3.2.0 and does not seem to affect 4.x.
External References:
http://www.pivotal.io/security/cve-2014-3578
https://jvn.jp/en/jp/JVN49154900/
---
Created springframework tracking bugs for this issue:
Affects: fedora-all [bug 1138950]
---
Red Hat JBoss BRMS 5 and Red Hat JBoss Enterprise Portal Platform 5 are now in Phase 3, Extended Life Suppor
http://jvn.jp/en/jp/JVN49154900/index.htmlhttp://jvndb.jvn.jp/jvndb/JVNDB-2014-000054http://pivotal.io/security/cve-2014-3578http://rhn.redhat.com/errata/RHSA-2015-0720.htmlhttp://www.securityfocus.com/bid/68042https://bugzilla.redhat.com/show_bug.cgi?id=1131882https://lists.debian.org/debian-lts-announce/2019/07/msg00012.htmlhttps://rhn.redhat.com/errata/RHSA-2015-0234.htmlhttps://rhn.redhat.com/errata/RHSA-2015-0235.htmlhttp://jvn.jp/en/jp/JVN49154900/index.htmlhttp://jvndb.jvn.jp/jvndb/JVNDB-2014-000054http://pivotal.io/security/cve-2014-3578http://rhn.redhat.com/errata/RHSA-2015-0720.htmlhttp://www.securityfocus.com/bid/68042https://bugzilla.redhat.com/show_bug.cgi?id=1131882https://lists.debian.org/debian-lts-announce/2019/07/msg00012.htmlhttps://rhn.redhat.com/errata/RHSA-2015-0234.htmlhttps://rhn.redhat.com/errata/RHSA-2015-0235.html
2015-02-19
Published