Lucene search

K
osvGoogleOSV:GHSA-76QR-MMH8-CP8F
HistoryOct 19, 2018 - 4:56 p.m.

Moderate severity vulnerability that affects com.sparkjava:spark-core

2018-10-1916:56:00
Google
osv.dev
8

0.006 Low

EPSS

Percentile

77.9%

In Spark before 2.7.2, a remote attacker can read unintended static files via various representations of absolute or relative pathnames, as demonstrated by file: URLs and directory traversal sequences. NOTE: this product is unrelated to Ignite Realtime Spark.

0.006 Low

EPSS

Percentile

77.9%