CVE-2016-9878
published 2016-12-29CVE-2016-9878: An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not…
PriorityP344high7.5CVSS 3.0
AVNACLPRNUINSUCHINAN
EPSS
5.64%
92.1th percentile
An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.
Affected
33 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libspring-java | < libspring-java 4.3.5-1 (bookworm) | libspring-java 4.3.5-1 (bookworm) |
| pivotal_software | spring_framework | <= 3.2.0 | — |
| pivotal_software | spring_framework | — | — |
| pivotal_software | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
| vmware | spring_framework | — | — |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv8.8HIGH
vendor_ubuntu8.8HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Spring Framework vulnerabilities
vendor_ubuntu·2021-03-17·CVSS 8.8
CVE-2015-5211 [HIGH] Spring Framework vulnerabilities
Title: Spring Framework vulnerabilities
Summary: Several security issues were fixed in Spring Framework.
Toshiaki Maki discovered that Spring Framework incorrectly handled certain
XML files. A remote attacker could exploit this with a crafted XML file to
cause a denial of service. (CVE-2015-3192)
Alvaro Muñoz discovered that Spring Framework incorrectly handled certain
URLs. A remote attacker could possibly use this issue to cause a reflected
file download. (CVE-2015-5211)
It was discovered that Spring Framework did not properly sanitize path
inputs. An attacker could possibly use this issue to read arbitrary files,
resulting in a directory traversal attack (CVE-2016-9878)
It was discovered that Spring Framework incorrectly handled XML documents.
An attacker could possibly use this is
Red Hat
Framework: Directory Traversal in the Spring Framework ResourceServlet
vendor_redhat·2016-12-21·CVSS 7.5
CVE-2016-9878 [HIGH] CWE-22 Framework: Directory Traversal in the Spring Framework ResourceServlet
Framework: Directory Traversal in the Spring Framework ResourceServlet
An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.
It was found that ResourceServlet in Spring Framework does not sanitize the paths that have been provided properly. An attacker can utilize this flaw to conduct a directory traversal attacks.
Package: springframework (Red Hat BPM Suite 6) - Not affected
Package: jasperreports-server-pro (Red Hat Enterprise Virtualization 3) - Under investigation
Package: karaf (Red Hat JBoss A-MQ 6) - Affected
Package: springframework (Red Hat JBoss BRMS 6) - Not affected
Package: springframework (Red
Debian
CVE-2016-9878: libspring-java - An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before ...
vendor_debian·2016·CVSS 7.5
CVE-2016-9878 [HIGH] CVE-2016-9878: libspring-java - An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before ...
An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.
Scope: local
bookworm: resolved (fixed in 4.3.5-1)
bullseye: resolved (fixed in 4.3.5-1)
forky: resolved (fixed in 4.3.5-1)
sid: resolved (fixed in 4.3.5-1)
trixie: resolved (fixed in 4.3.5-1)
OSV
libspring-java vulnerabilities
osv·2021-03-17·CVSS 8.8
CVE-2015-3192 [HIGH] libspring-java vulnerabilities
libspring-java vulnerabilities
Toshiaki Maki discovered that Spring Framework incorrectly handled certain
XML files. A remote attacker could exploit this with a crafted XML file to
cause a denial of service. (CVE-2015-3192)
Alvaro Muñoz discovered that Spring Framework incorrectly handled certain
URLs. A remote attacker could possibly use this issue to cause a reflected
file download. (CVE-2015-5211)
It was discovered that Spring Framework did not properly sanitize path
inputs. An attacker could possibly use this issue to read arbitrary files,
resulting in a directory traversal attack (CVE-2016-9878)
It was discovered that Spring Framework incorrectly handled XML documents.
An attacker could possibly use this issue to generate an XML external
entity attack, resulting in a denial of ser
GHSA
Pivotal Spring Framework Paths provided to the ResourceServlet were not properly sanitized
ghsa·2018-10-04
CVE-2016-9878 [HIGH] CWE-22 Pivotal Spring Framework Paths provided to the ResourceServlet were not properly sanitized
Pivotal Spring Framework Paths provided to the ResourceServlet were not properly sanitized
An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.
OSV
Pivotal Spring Framework Paths provided to the ResourceServlet were not properly sanitized
osv·2018-10-04
CVE-2016-9878 [HIGH] Pivotal Spring Framework Paths provided to the ResourceServlet were not properly sanitized
Pivotal Spring Framework Paths provided to the ResourceServlet were not properly sanitized
An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.
OSV
CVE-2016-9878: An issue was discovered in Pivotal Spring Framework before 3
osv·2016-12-29·CVSS 7.5
CVE-2016-9878 [HIGH] CVE-2016-9878: An issue was discovered in Pivotal Spring Framework before 3
An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-9878 springframework: Spring Framework: Directory Traversal in the Spring Framework ResourceServlet [fedora-all]
bugzilla·2016-12-22·CVSS 7.5
CVE-2016-9878 [HIGH] CVE-2016-9878 springframework: Spring Framework: Directory Traversal in the Spring Framework ResourceServlet [fedora-all]
CVE-2016-9878 springframework: Spring Framework: Directory Traversal in the Spring Framework ResourceServlet [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this i
Bugzilla
CVE-2016-9878 Spring Framework: Directory Traversal in the Spring Framework ResourceServlet
bugzilla·2016-12-22·CVSS 7.5
CVE-2016-9878 [HIGH] CVE-2016-9878 Spring Framework: Directory Traversal in the Spring Framework ResourceServlet
CVE-2016-9878 Spring Framework: Directory Traversal in the Spring Framework ResourceServlet
It was found that paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.
Upstream bug:
https://jira.spring.io/browse/SPR-14946
Upstream patches:
https://github.com/spring-projects/spring-framework/commit/e2d6e709c3c65a4951eb096843ee75d5200cfcad
https://github.com/spring-projects/spring-framework/commit/43bf008fbcd0d7945e2fcd5e30039bc4d74c7a98
https://github.com/spring-projects/spring-framework/commit/a7dc48534ea501525f11369d369178a60c2f47d0
External References:
https://pivotal.io/security/cve-2016-9878
Discussion:
Created springframework tracking bugs for this issue:
Affects: fedora-all [bug 1408165]
---
Could not find an
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.securityfocus.com/bid/95072http://www.securitytracker.com/id/1040698https://access.redhat.com/errata/RHSA-2017:3115https://lists.debian.org/debian-lts-announce/2019/07/msg00012.htmlhttps://pivotal.io/security/cve-2016-9878https://security.netapp.com/advisory/ntap-20180419-0002/https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.htmlhttp://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.htmlhttp://www.securityfocus.com/bid/95072http://www.securitytracker.com/id/1040698https://access.redhat.com/errata/RHSA-2017:3115https://lists.debian.org/debian-lts-announce/2019/07/msg00012.htmlhttps://pivotal.io/security/cve-2016-9878https://security.netapp.com/advisory/ntap-20180419-0002/https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
2016-12-29
Published