Directory Traversal with Spring MVC... CVE-2018-1271 CNNVD-201804-244

4.3 AV AC AU C I A
发布: 2018-04-06
修订: 2020-07-15

### Severity High ### Vendor Spring by Pivotal ### Description Spring Framework versions 5.0 to 5.0.4, 4.3 to 4.3.14, and older unsupported versions allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a request using a specially crafted URL that can lead a directory traversal attack. ### Affected Pivotal Products and Versions * Severity is high unless otherwise noted. * Spring Framework 5.0 to 5.0.4 * Spring Framework 4.3 to 4.3.14 * Older unsupported versions are also affected ### Mitigation Users of affected versions should apply the following mitigation: * 5.0.x users should upgrade to 5.0.5 * 4.3.x users should upgrade to 4.3.15 * Older versions should upgrade to a supported branch There are no other mitigation steps necessary. Note also that this attack does not apply to applications that: Do not...

0%
当前有1条漏洞利用/PoC
当前有68条受影响产品信息