Published: 04/11/2016 Updated: 05/01/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in Spark 2.5 allows remote malicious users to read arbitrary files via a .. (dot dot) in the URI.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.
Vulnerable Product Search on Vulmon Subscribe to Product

Vendor Advisories

A path traversal issue was found in Spark version 25 and potentially earlier versions The vulnerability resides in the functionality to serve static files where there's no protection against directory traversal attacks This could allow attackers access to private files including sensitive data ...