Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.
2014-11-20T17:50:00.113
2025-04-12T10:46:40.837
Deferred
CVSSv2: 5.0 (MEDIUM)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | pivotal_software | spring_framework | ≤ 3.1.4 | Yes |
Application | pivotal_software | spring_framework | < 3.2.12 | Yes |
Application | pivotal_software | spring_framework | < 4.0.8 | Yes |
Application | pivotal_software | spring_framework | < 4.1.2 | Yes |
Application | vmware | spring_framework | ≤ 3.0.7 | Yes |