PT-2025-33358 · Apache +3 · Apache Tomcat +3

1Ue

+2

·

Published

2025-08-14

·

Updated

2025-08-24

·

CVE-2025-41242

CVSS v3.1
5.9
VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Name of the Vulnerable Software and Affected Versions:

Spring Framework MVC applications (affected versions not specified)

Description:

Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deployed on a non-compliant Servlet container. This issue occurs when the application is deployed as a WAR or with an embedded Servlet container, the Servlet container does not reject suspicious sequences, and the application serves static resources with Spring resource handling. Applications deployed on Apache Tomcat or Eclipse Jetty are not vulnerable, assuming default security features are not disabled.

Recommendations:

At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-41242
GHSA-R936-GWX5-V52F

Affected Products

Apache Tomcat
Debian
Eclipse Jetty
Spring Framework