VulnerabilityModified
CVE-2014-3578
Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.
MEDIUM 5.0EPSS 6.33%
Does this matter?
Lower severity and a low EPSS score (6.33%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 6.33% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- pivotal software/spring framework
- Source
- secalert@redhat.com
References
- http://jvn.jp/en/jp/JVN49154900/index.htmlThird Party Advisory, VDB Entry
- http://jvndb.jvn.jp/jvndb/JVNDB-2014-000054Third Party Advisory, VDB Entry
- http://pivotal.io/security/cve-2014-3578Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0720.htmlThird Party Advisory
- http://www.securityfocus.com/bid/68042Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1131882Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/07/msg00012.html
- https://rhn.redhat.com/errata/RHSA-2015-0234.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2015-0235.htmlThird Party Advisory
- http://jvn.jp/en/jp/JVN49154900/index.htmlThird Party Advisory, VDB Entry
- http://jvndb.jvn.jp/jvndb/JVNDB-2014-000054Third Party Advisory, VDB Entry
- http://pivotal.io/security/cve-2014-3578Vendor Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0720.htmlThird Party Advisory
- http://www.securityfocus.com/bid/68042Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1131882Issue Tracking, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/07/msg00012.html
- https://rhn.redhat.com/errata/RHSA-2015-0234.htmlThird Party Advisory
- https://rhn.redhat.com/errata/RHSA-2015-0235.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.