Overview
About vulnerability
Applications using Spring Framework’s FreeMarker integration may be vulnerable to a path traversal attack when a controller returns a view name derived from untrusted input and FreeMarker is configured to resolve templates through SpringTemplateLoader. Under these conditions, a view name containing backslash sequences can escape the configured template directory, potentially exposing files that should not be accessible.
Returning a view name derived from untrusted input is an application-level anti-pattern that Spring documentation warns against; applications that do not do so are not affected.
Details
- Affected product:
- Apache CXF , Apache Log4j , Apache Struts , Apache Tomcat , Eclipse Jetty , Spring , activemq , amqp-10-jms-spring-boot , artemis , azure-spring-data-cosmos , camel , cocoon , crash , cypher-dsl , glassfish-hk2 , grails-core , grails-data-mapping , grails-gsp , grails-plugin-converters , java-sdk , jersey , karaf , micronaut-spring , pulsar , tika
- Affected packages:
- Spring Framework @ 6.2.15 (+11466 more)