CVE-2024-38819High· 7.5▾ MidnightPoC availableSpring Framework Path Traversal vulnerability
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 11.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 2 sources. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
56%
5 GitHub repos · Nuclei ×1 (last check)
Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.
org.springframework:spring-webflux >= 6.1.0, < 6.1.14org.springframework:spring-webmvc >= 6.1.0, < 6.1.14org.springframework:spring-webflux <= 5.3.40org.springframework:spring-webmvc <= 5.3.40org.springframework:spring-webflux >= 6.0.0, <= 6.0.24org.springframework:spring-webmvc >= 6.0.0, <= 6.0.24Upgrade to a patched release:
org.springframework:spring-webflux 6.1.14org.springframework:spring-webmvc 6.1.14Connected by shared product, vendor, weakness, or advisory.
CVE-2010-2861Critical· 9.8Multiple directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier allow remote attackers to read arbitrary files via the locale parameter to (1) CFIDE/administrator/settings/mappings.cfm, (2)…
CVE-2021-27065High· 7.8Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2021-21972Critical· 9.8The vSphere Client (HTML5) contains a remote code execution vulnerability in a vCenter Server plugin
CVE-2019-19781Critical· 9.8An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0
CVE-2020-3187Critical· 9.1A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct directory traversal attacks an…
CVE-2021-40444High· 8.8Microsoft is investigating reports of a remote code execution vulnerability in MSHTML that affects Microsoft Windows