- CVE ID
- CVE-2014-3578
- CVE Description
- Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.
- Published
- Mar 28, 2017
- CVSS Score & Severity
5.0Medium
- CVSS Vector
- AV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS Score
- 4.358%
- KEV Status
Not in KEV Catalog: No known exploits
- Vulnerable Methods
org/springframework/util/StringUtils.cleanPath(Ljava/lang/String;)Ljava/lang/String;JVMVulnerable params: 0
- Source
- National Vulnerability Database