SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2018-1271

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g.

MEDIUM 5.9EPSS 34.6%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 34.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a request using a specially crafted URL that can lead a directory traversal attack.

CVSS 3.1
5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
34.64% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-22
Affected
vmware/spring framework · oracle/application testing suite · oracle/big data discovery · oracle/communications converged application server · oracle/communications diameter signaling router · oracle/communications performance intelligence center · oracle/communications policy management · oracle/communications services gatekeeper · oracle/enterprise manager ops center · oracle/goldengate for big data · oracle/health sciences information manager · oracle/healthcare master person index · oracle/insurance calculation engine · oracle/insurance rules palette · oracle/primavera gateway · oracle/rapid planning · oracle/retail back office · oracle/retail central office · oracle/retail customer insights · oracle/retail integration bus · +8 more
Source
security_alert@emc.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.