CVE-2014-3578

CWE-22Path Traversal10 documents8 sources
Severity
5.0MEDIUM
EPSS
4.4%
top 11.05%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 19
Latest updateMay 14

Description

Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

NVDpivotal_software/spring_framework3.2.03.2.9+1
Mavenorg.springframework:spring-core3.0.03.2.9+1
Debianlibspring-java< 3.2.13-1+3

🔴Vulnerability Details

4
OSV
Improper Limitation of a Pathname to a Restricted Directory in Spring Framework2022-05-14
GHSA
Improper Limitation of a Pathname to a Restricted Directory in Spring Framework2022-05-14
OSV
CVE-2014-3578: Directory traversal vulnerability in Pivotal Spring Framework 32015-02-19
CVEList
CVE-2014-3578: Directory traversal vulnerability in Pivotal Spring Framework 32015-02-19

📋Vendor Advisories

3
Ubuntu
Spring Framework vulnerabilities2021-03-17
Red Hat
Framework: Directory traversal2014-09-05
Debian
CVE-2014-3578: libspring-java - Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 a...2014

💬Community

2
Bugzilla
CVE-2014-3578 springframework: Spring Framework: Directory traversal [fedora-all]2014-09-06
Bugzilla
CVE-2014-3578 Spring Framework: Directory traversal2014-08-20