CVE-2014-3625
medium · 5Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.
5
CVSS
10.3%
EPSS (exploit prob.)
95th
EPSS percentile
2014-11-20
Published
AV:N/AC:L/Au:N/C:P/I:N/A:N
Weaknesses
CWE-22
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| pivotal_software | spring_framework | >= 3.1.0, <= 3.1.4 |
| pivotal_software | spring_framework | >= 3.2.0, < 3.2.12 |
| pivotal_software | spring_framework | >= 4.0.0, < 4.0.8 |
| pivotal_software | spring_framework | >= 4.1.0, < 4.1.2 |
| vmware | spring_framework | >= 3.0.4, <= 3.0.7 |
Check a specific version with /api/v1/cve/match.
References
- http://rhn.redhat.com/errata/RHSA-2015-0236.html
- http://rhn.redhat.com/errata/RHSA-2015-0720.html
- http://www.pivotal.io/security/cve-2014-3625
- https://jira.spring.io/browse/SPR-12354
- https://lists.debian.org/debian-lts-announce/2019/07/msg00012.html
- http://rhn.redhat.com/errata/RHSA-2015-0236.html
- http://rhn.redhat.com/errata/RHSA-2015-0720.html
- http://www.pivotal.io/security/cve-2014-3625
- https://jira.spring.io/browse/SPR-12354
- https://lists.debian.org/debian-lts-announce/2019/07/msg00012.html
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2014-3625