{"id":"GHSA-rhcg-rwhx-qj3j","summary":"Improper Limitation of a Pathname to a Restricted Directory in Spring Framework","details":"Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.","aliases":["CVE-2014-3578"],"modified":"2024-12-06T05:51:08.822813Z","published":"2022-05-14T00:56:29Z","database_specific":{"cwe_ids":["CWE-22"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-07-07T22:40:29Z","nvd_published_at":"2015-02-19T20:59:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-3578"},{"type":"WEB","url":"https://github.com/spring-projects/spring-framework/issues/16414"},{"type":"WEB","url":"https://github.com/spring-projects/spring-framework/commit/748167bfa33c3c69db2d8dbdc3a0e9da692da3a0"},{"type":"WEB","url":"https://github.com/spring-projects/spring-framework/commit/8ee465103850a3dca018273fe5952e40d5c45a66"},{"type":"WEB","url":"https://github.com/spring-projects/spring-framework/commit/f6fddeb6eb7da625fd711ab371ff16512f431e8d"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1131882"},{"type":"PACKAGE","url":"https://github.com/spring-projects/spring-framework"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2019/07/msg00012.html"},{"type":"WEB","url":"https://rhn.redhat.com/errata/RHSA-2015-0234.html"},{"type":"WEB","url":"https://rhn.redhat.com/errata/RHSA-2015-0235.html"},{"type":"WEB","url":"http://jvn.jp/en/jp/JVN49154900/index.html"},{"type":"WEB","url":"http://jvndb.jvn.jp/jvndb/JVNDB-2014-000054"},{"type":"WEB","url":"http://pivotal.io/security/cve-2014-3578"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2015-0720.html"}],"affected":[{"package":{"name":"org.springframework:spring-core","ecosystem":"Maven","purl":"pkg:maven/org.springframework/spring-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.2.9"}]}],"versions":["3.0.0.RELEASE","3.0.1.RELEASE","3.0.2.RELEASE","3.0.3.RELEASE","3.0.4.RELEASE","3.0.5.RELEASE","3.0.6.RELEASE","3.0.7.RELEASE","3.1.0.RELEASE","3.1.1.RELEASE","3.1.2.RELEASE","3.1.3.RELEASE","3.1.4.RELEASE","3.2.0.RELEASE","3.2.1.RELEASE","3.2.2.RELEASE","3.2.3.RELEASE","3.2.4.RELEASE","3.2.5.RELEASE","3.2.6.RELEASE","3.2.7.RELEASE","3.2.8.RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rhcg-rwhx-qj3j/GHSA-rhcg-rwhx-qj3j.json"}},{"package":{"name":"org.springframework:spring-core","ecosystem":"Maven","purl":"pkg:maven/org.springframework/spring-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"4.0.5"}]}],"versions":["4.0.0.RELEASE","4.0.1.RELEASE","4.0.2.RELEASE","4.0.3.RELEASE","4.0.4.RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-rhcg-rwhx-qj3j/GHSA-rhcg-rwhx-qj3j.json"}}],"schema_version":"1.9.0"}