CVE-2014-3625
Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.3%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 10.32% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- pivotal software/spring framework · vmware/spring framework
- Source
- secalert@redhat.com
References
- http://rhn.redhat.com/errata/RHSA-2015-0236.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0720.htmlThird Party Advisory
- http://www.pivotal.io/security/cve-2014-3625Vendor Advisory
- https://jira.spring.io/browse/SPR-12354Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/07/msg00012.html
- http://rhn.redhat.com/errata/RHSA-2015-0236.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0720.htmlThird Party Advisory
- http://www.pivotal.io/security/cve-2014-3625Vendor Advisory
- https://jira.spring.io/browse/SPR-12354Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/07/msg00012.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.