CVE-2014-3578: Path Traversal
Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.
Other sources
It was discovered that Spring Framework contained an undisclosed directory traversal vulnerability. A remote attacker could use this flaw to access arbitrary files on a server bypassing security restrictions that are otherwise in place.
References:
http://jvndb.jvn.jp/en/contents/2014/JVNDB-2014-000054.html
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3578?
CVE-2014-3578 is classified as a medium severity vulnerability due to its potential impact on sensitive file exposure.
How do I fix CVE-2014-3578?
To fix CVE-2014-3578, upgrade the Spring Framework to version 3.2.9 or later, or 4.0.5 or later.
What are the affected versions of Spring Framework in CVE-2014-3578?
The affected versions of Spring Framework are versions before 3.2.9 and before 4.0.5.
What type of attack does CVE-2014-3578 allow?
CVE-2014-3578 allows remote attackers to exploit a directory traversal vulnerability to read arbitrary files.
Is there a public exploit available for CVE-2014-3578?
As of now, there are no known public exploit details available for CVE-2014-3578.