CVE-2014-3625

CWE-22Path Traversal9 documents8 sources
Severity
5.0MEDIUM
EPSS
17.0%
top 5.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 20
Latest updateMay 13

Description

Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.

CVSS vector

AV:N/AC:L/C:P/I:N/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages4 packages

NVDpivotal_software/spring_framework3.2.03.2.12+3
Mavenorg.springframework:spring-webmvc3.0.43.2.12+2
NVDvmware/spring_framework3.0.43.0.7
Debianlibspring-java< 3.2.13-1+3

🔴Vulnerability Details

4
GHSA
Improper Limitation of a Pathname to a Restricted Directory in Spring Framework2022-05-13
OSV
Improper Limitation of a Pathname to a Restricted Directory in Spring Framework2022-05-13
OSV
CVE-2014-3625: Directory traversal vulnerability in Pivotal Spring Framework 32014-11-20
CVEList
CVE-2014-3625: Directory traversal vulnerability in Pivotal Spring Framework 32014-11-20

📋Vendor Advisories

3
Ubuntu
Spring Framework vulnerabilities2021-03-17
Red Hat
Framework: directory traversal flaw2014-11-11
Debian
CVE-2014-3625: libspring-java - Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2....2014

💬Community

1
Bugzilla
CVE-2014-3625 Spring Framework: directory traversal flaw2014-11-20