An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.

Project Subscriptions

Vendors Products
Pivotal Software Subscribe
Spring Framework Subscribe
Jboss Amq Subscribe
Jboss Fuse Subscribe
Spring Framework Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-1853-1 libspring-java security update
EUVD EUVD EUVD-2018-0477 An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.
Github GHSA Github GHSA GHSA-2m8h-fgr8-2q9w Pivotal Spring Framework Paths provided to the ResourceServlet were not properly sanitized
Ubuntu USN Ubuntu USN USN-4774-1 Spring Framework vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-08-06T03:07:30.827Z

Reserved: 2016-12-06T00:00:00.000Z

Link: CVE-2016-9878

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2016-12-29T09:59:00.820

Modified: 2025-04-12T10:46:40.837

Link: CVE-2016-9878

cve-icon Redhat

Severity : Moderate

Publid Date: 2016-12-21T00:00:00Z

Links: CVE-2016-9878 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses