PT-2018-11345 · Spring · Spring Framework
Published
2018-04-06
·
Updated
2025-06-28
·
CVE-2018-1271
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Spring Framework versions 5.0 prior to 5.0.5
Spring Framework versions 4.3 prior to 4.3.15
Spring Framework older unsupported versions
Description
The issue allows applications to configure Spring MVC to serve static resources. A malicious user can send a request using a specially crafted URL that can lead to a directory traversal attack when static resources are served from a file system on Windows.
Recommendations
For Spring Framework versions 5.0 prior to 5.0.5, update to version 5.0.5 or later.
For Spring Framework versions 4.3 prior to 4.3.15, update to version 4.3.15 or later.
For Spring Framework older unsupported versions, consider upgrading to a supported version.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spring Framework