CVE-2014-3625
published 2014-11-20CVE-2014-3625: Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote…
PriorityP336medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
10.05%
95.1th percentile
Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libspring-java | < libspring-java 3.2.13-1 (bookworm) | libspring-java 3.2.13-1 (bookworm) |
| pivotal_software | spring_framework | 3.1.0 – 3.1.4 | — |
| pivotal_software | spring_framework | >= 3.2.0 < 3.2.12 | 3.2.12 |
| pivotal_software | spring_framework | >= 4.0.0 < 4.0.8 | 4.0.8 |
| pivotal_software | spring_framework | >= 4.1.0 < 4.1.2 | 4.1.2 |
| vmware | spring_framework | 3.0.4 – 3.0.7 | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper Limitation of a Pathname to a Restricted Directory in Spring Framework
ghsa·2022-05-13
CVE-2014-3625 [MEDIUM] CWE-22 Improper Limitation of a Pathname to a Restricted Directory in Spring Framework
Improper Limitation of a Pathname to a Restricted Directory in Spring Framework
Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.
OSV
Improper Limitation of a Pathname to a Restricted Directory in Spring Framework
osv·2022-05-13
CVE-2014-3625 [MEDIUM] Improper Limitation of a Pathname to a Restricted Directory in Spring Framework
Improper Limitation of a Pathname to a Restricted Directory in Spring Framework
Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.
OSV
libspring-java vulnerabilities
osv·2021-03-17·CVSS 8.8
CVE-2015-3192 [HIGH] libspring-java vulnerabilities
libspring-java vulnerabilities
Toshiaki Maki discovered that Spring Framework incorrectly handled certain
XML files. A remote attacker could exploit this with a crafted XML file to
cause a denial of service. (CVE-2015-3192)
Alvaro Muñoz discovered that Spring Framework incorrectly handled certain
URLs. A remote attacker could possibly use this issue to cause a reflected
file download. (CVE-2015-5211)
It was discovered that Spring Framework did not properly sanitize path
inputs. An attacker could possibly use this issue to read arbitrary files,
resulting in a directory traversal attack (CVE-2016-9878)
It was discovered that Spring Framework incorrectly handled XML documents.
An attacker could possibly use this issue to generate an XML external
entity attack, resulting in a denial of ser
OSV
CVE-2014-3625: Directory traversal vulnerability in Pivotal Spring Framework 3
osv·2014-11-20·CVSS 5.0
CVE-2014-3625 [MEDIUM] CVE-2014-3625: Directory traversal vulnerability in Pivotal Spring Framework 3
Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.
Ubuntu
Spring Framework vulnerabilities
vendor_ubuntu·2021-03-17·CVSS 8.8
CVE-2015-5211 [HIGH] Spring Framework vulnerabilities
Title: Spring Framework vulnerabilities
Summary: Several security issues were fixed in Spring Framework.
Toshiaki Maki discovered that Spring Framework incorrectly handled certain
XML files. A remote attacker could exploit this with a crafted XML file to
cause a denial of service. (CVE-2015-3192)
Alvaro Muñoz discovered that Spring Framework incorrectly handled certain
URLs. A remote attacker could possibly use this issue to cause a reflected
file download. (CVE-2015-5211)
It was discovered that Spring Framework did not properly sanitize path
inputs. An attacker could possibly use this issue to read arbitrary files,
resulting in a directory traversal attack (CVE-2016-9878)
It was discovered that Spring Framework incorrectly handled XML documents.
An attacker could possibly use this is
Red Hat
Framework: directory traversal flaw
vendor_redhat·2014-11-11·CVSS 5.0
CVE-2014-3625 [MEDIUM] CWE-22 Framework: directory traversal flaw
Framework: directory traversal flaw
Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.
A directory traversal flaw was found in the way the Spring Framework sanitized certain URLs. A remote attacker could use this flaw to obtain any file on the file system that was also accessible to the process in which the Spring web application was running.
Package: spring (Red Hat JBoss BRMS 5) - Will not fix
Package: spring (Red Hat JBoss Portal 5) - Will not fix
Package: spring (Red Hat JBoss Portal 6) - Affected
Debian
CVE-2014-3625: libspring-java - Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2....
vendor_debian·2014·CVSS 5.0
CVE-2014-3625 [MEDIUM] CVE-2014-3625: libspring-java - Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2....
Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.
Scope: local
bookworm: resolved (fixed in 3.2.13-1)
bullseye: resolved (fixed in 3.2.13-1)
forky: resolved (fixed in 3.2.13-1)
sid: resolved (fixed in 3.2.13-1)
trixie: resolved (fixed in 3.2.13-1)
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2015-0236.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0720.htmlhttp://www.pivotal.io/security/cve-2014-3625https://jira.spring.io/browse/SPR-12354https://lists.debian.org/debian-lts-announce/2019/07/msg00012.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0236.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0720.htmlhttp://www.pivotal.io/security/cve-2014-3625https://jira.spring.io/browse/SPR-12354https://lists.debian.org/debian-lts-announce/2019/07/msg00012.html
2014-11-20
Published