{"id":"GHSA-76qr-mmh8-cp8f","summary":"Moderate severity vulnerability that affects com.sparkjava:spark-core","details":"In Spark before 2.7.2, a remote attacker can read unintended static files via various representations of absolute or relative pathnames, as demonstrated by file: URLs and directory traversal sequences. NOTE: this product is unrelated to Ignite Realtime Spark.","aliases":["CVE-2018-9159"],"modified":"2023-11-01T04:49:42.721247Z","published":"2018-10-19T16:56:00Z","database_specific":{"github_reviewed_at":"2020-06-16T21:21:39Z","nvd_published_at":null,"cwe_ids":["CWE-22"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-9159"},{"type":"WEB","url":"https://github.com/perwendel/spark/issues/981"},{"type":"WEB","url":"https://github.com/perwendel/spark/commit/030e9d00125cbd1ad759668f85488aba1019c668"},{"type":"WEB","url":"https://github.com/perwendel/spark/commit/a221a864db28eb736d36041df2fa6eb8839fc5cd"},{"type":"WEB","url":"https://github.com/perwendel/spark/commit/ce9e11517eca69e58ed4378d1e47a02bd06863cc"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:2020"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2018:2405"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-76qr-mmh8-cp8f"},{"type":"PACKAGE","url":"https://github.com/perwendel/spark"},{"type":"WEB","url":"http://sparkjava.com/news#spark-272-released"}],"affected":[{"package":{"name":"com.sparkjava:spark-core","ecosystem":"Maven","purl":"pkg:maven/com.sparkjava/spark-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.7.2"}]}],"versions":["1.0","1.1","1.1.1","2.0.0","2.1","2.2","2.3","2.4","2.5","2.5.1","2.5.2","2.5.3","2.5.4","2.5.5","2.6.0","2.6.0.RC0","2.7.0","2.7.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-76qr-mmh8-cp8f/GHSA-76qr-mmh8-cp8f.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}