Lucene search

K
osvGoogleOSV:GHSA-HHM4-HWQ6-3C6W
HistoryMay 13, 2022 - 1:02 a.m.

Improper Limitation of a Pathname to a Restricted Directory in Spring Framework

2022-05-1301:02:39
Google
osv.dev
15

0.005 Low

EPSS

Percentile

76.0%

Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.