CVE-2014-3578

Updated on 19 Feb 2015

Severity

Awaiting Analysis

Details

CVSS score
8.6

Overview

About vulnerability

Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.

Details

Affected product:
Eclipse Jetty , Spring , activemq , cocoon , cxf , karaf
Affected packages:
cocoon-xsp-sample @ 2.3.0 (+534 more)
Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.

Fixes