{"id":"GHSA-hhm4-hwq6-3c6w","summary":"Improper Limitation of a Pathname to a Restricted Directory in Spring Framework","details":"Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.","aliases":["CVE-2014-3625"],"modified":"2024-12-03T06:04:13.404209Z","published":"2022-05-13T01:02:39Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-07-07T22:37:37Z","nvd_published_at":"2014-11-20T17:50:00Z","cwe_ids":["CWE-22"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-3625"},{"type":"WEB","url":"https://github.com/spring-projects/spring-framework/commit/161d3e3049f129e211f68a4e94b544e0f0d8384d"},{"type":"WEB","url":"https://github.com/spring-projects/spring-framework/commit/3f68cd633f03370d33c2603a6496e81273782601"},{"type":"WEB","url":"https://github.com/spring-projects/spring-framework/commit/9beae9ae4226c45cd428035dae81214439324676"},{"type":"WEB","url":"https://github.com/spring-projects/spring-framework/commit/9cef8e3001ddd61c734281a7556efd84b6cc2755"},{"type":"PACKAGE","url":"https://github.com/spring-projects/spring-framework"},{"type":"WEB","url":"https://jira.spring.io/browse/SPR-12354"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2019/07/msg00012.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-0236.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-0720.html"},{"type":"WEB","url":"http://www.pivotal.io/security/cve-2014-3625"}],"affected":[{"package":{"name":"org.springframework:spring-webmvc","ecosystem":"Maven","purl":"pkg:maven/org.springframework/spring-webmvc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.4"},{"fixed":"3.2.12"}]}],"versions":["3.0.4.RELEASE","3.0.5.RELEASE","3.0.6.RELEASE","3.0.7.RELEASE","3.1.0.RELEASE","3.1.1.RELEASE","3.1.2.RELEASE","3.1.3.RELEASE","3.1.4.RELEASE","3.2.0.RELEASE","3.2.1.RELEASE","3.2.10.RELEASE","3.2.11.RELEASE","3.2.2.RELEASE","3.2.3.RELEASE","3.2.4.RELEASE","3.2.5.RELEASE","3.2.6.RELEASE","3.2.7.RELEASE","3.2.8.RELEASE","3.2.9.RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-hhm4-hwq6-3c6w/GHSA-hhm4-hwq6-3c6w.json"}},{"package":{"name":"org.springframework:spring-webmvc","ecosystem":"Maven","purl":"pkg:maven/org.springframework/spring-webmvc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"4.0.8"}]}],"versions":["4.0.0.RELEASE","4.0.1.RELEASE","4.0.2.RELEASE","4.0.3.RELEASE","4.0.4.RELEASE","4.0.5.RELEASE","4.0.6.RELEASE","4.0.7.RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-hhm4-hwq6-3c6w/GHSA-hhm4-hwq6-3c6w.json"}},{"package":{"name":"org.springframework:spring-webmvc","ecosystem":"Maven","purl":"pkg:maven/org.springframework/spring-webmvc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.1.0"},{"fixed":"4.1.2"}]}],"versions":["4.1.0.RELEASE","4.1.1.RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-hhm4-hwq6-3c6w/GHSA-hhm4-hwq6-3c6w.json"}}],"schema_version":"1.9.0"}