{"id":"GHSA-2m8h-fgr8-2q9w","summary":"Pivotal Spring Framework Paths provided to the ResourceServlet were not properly sanitized","details":"An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.","aliases":["CVE-2016-9878"],"modified":"2024-03-05T18:01:15.447388Z","published":"2018-10-04T20:29:55Z","database_specific":{"github_reviewed_at":"2020-06-16T20:52:31Z","nvd_published_at":"2016-12-29T09:59:00Z","cwe_ids":["CWE-22"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-9878"},{"type":"WEB","url":"https://github.com/spring-projects/spring-framework/issues/19513"},{"type":"WEB","url":"https://github.com/spring-projects/spring-framework/commit/43bf008fbcd0d7945e2fcd5e30039bc4d74c7a98"},{"type":"WEB","url":"https://github.com/spring-projects/spring-framework/commit/a7dc48534ea501525f11369d369178a60c2f47d0"},{"type":"WEB","url":"https://github.com/spring-projects/spring-framework/commit/e2d6e709c3c65a4951eb096843ee75d5200cfcad"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2017:3115"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2m8h-fgr8-2q9w"},{"type":"PACKAGE","url":"https://github.com/spring-projects/spring-framework"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2019/07/msg00012.html"},{"type":"WEB","url":"https://pivotal.io/security/cve-2016-9878"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20180419-0002"},{"type":"WEB","url":"https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html"},{"type":"WEB","url":"http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html"},{"type":"WEB","url":"http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.html"},{"type":"WEB","url":"http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html"},{"type":"WEB","url":"http://www.securityfocus.com/bid/95072"},{"type":"WEB","url":"http://www.securitytracker.com/id/1040698"}],"affected":[{"package":{"name":"org.springframework:spring-webmvc","ecosystem":"Maven","purl":"pkg:maven/org.springframework/spring-webmvc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.2.18"}]}],"versions":["1.0","1.0-rc1","1.0.1","1.1","1.1-rc1","1.1-rc2","1.1.1","1.1.2","1.1.3","1.1.4","1.1.5","1.2","1.2-rc1","1.2-rc2","1.2.1","1.2.2","1.2.3","1.2.4","1.2.5","1.2.6","1.2.7","1.2.8","1.2.9","2.0","2.0-m1","2.0-m2","2.0-m3","2.0-m4","2.0-m5","2.0-rc1","2.0-rc2","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.0.7","2.0.8","2.5","2.5.1","2.5.2","2.5.3","2.5.4","2.5.5","2.5.6","2.5.6.SEC01","2.5.6.SEC02","2.5.6.SEC03","3.0.0.RELEASE","3.0.1.RELEASE","3.0.2.RELEASE","3.0.3.RELEASE","3.0.4.RELEASE","3.0.5.RELEASE","3.0.6.RELEASE","3.0.7.RELEASE","3.1.0.RELEASE","3.1.1.RELEASE","3.1.2.RELEASE","3.1.3.RELEASE","3.1.4.RELEASE","3.2.0.RELEASE","3.2.1.RELEASE","3.2.10.RELEASE","3.2.11.RELEASE","3.2.12.RELEASE","3.2.13.RELEASE","3.2.14.RELEASE","3.2.15.RELEASE","3.2.16.RELEASE","3.2.17.RELEASE","3.2.2.RELEASE","3.2.3.RELEASE","3.2.4.RELEASE","3.2.5.RELEASE","3.2.6.RELEASE","3.2.7.RELEASE","3.2.8.RELEASE","3.2.9.RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-2m8h-fgr8-2q9w/GHSA-2m8h-fgr8-2q9w.json"}},{"package":{"name":"org.springframework:spring-webmvc","ecosystem":"Maven","purl":"pkg:maven/org.springframework/spring-webmvc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.2.0"},{"fixed":"4.2.9"}]}],"versions":["4.2.0.RELEASE","4.2.1.RELEASE","4.2.2.RELEASE","4.2.3.RELEASE","4.2.4.RELEASE","4.2.5.RELEASE","4.2.6.RELEASE","4.2.7.RELEASE","4.2.8.RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-2m8h-fgr8-2q9w/GHSA-2m8h-fgr8-2q9w.json"}},{"package":{"name":"org.springframework:spring-webmvc","ecosystem":"Maven","purl":"pkg:maven/org.springframework/spring-webmvc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.3.0"},{"fixed":"4.3.5"}]}],"versions":["4.3.0.RELEASE","4.3.1.RELEASE","4.3.2.RELEASE","4.3.3.RELEASE","4.3.4.RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-2m8h-fgr8-2q9w/GHSA-2m8h-fgr8-2q9w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}