5
CVSSv2

CVE-2014-3578

Published: 19/02/2015 Updated: 14/07/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in Pivotal Spring Framework 3.x prior to 3.2.9 and 4.0 prior to 4.0.5 allows remote malicious users to read arbitrary files via a crafted URL.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pivotal software spring framework

Vendor Advisories

Debian Bug report logs - #769698 libspring-java: CVE-2014-3625 Directory Traversal in Spring Framework Package: src:libspring-java; Maintainer for src:libspring-java is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: bastien ROUCARIÈS <roucariesbastien+debian@gmailcom> Date: Sat ...
Debian Bug report logs - #760733 CVE-2014-3578: directory traversal Package: src:libspring-java; Maintainer for src:libspring-java is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Yves-Alexis Perez <corsac@debianorg> Date: Sun, 7 Sep 2014 11:33:05 UTC Severity: important Tags: ...
Debian Bug report logs - #753470 libspring-java: CVE-2014-0225 Package: libspring-java; Maintainer for libspring-java is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@inutilorg> Date: Wed, 2 Jul 2014 08:54:02 UTC Severity: grave Tags: patch, security F ...
A directory traversal flaw was found in the Spring Framework A remote attacker could use this flaw to access arbitrary files on a server, and bypassing security restrictions that are otherwise in place ...