CVE-2024-38819
Spring Framework Path Traversal vulnerability
7.5
HIGH
CVSS 3.1
EPSS 93.2%
Description
Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.
How to fix CVE-2024-38819
To remediate CVE-2024-38819, upgrade the affected package to a fixed version below.
- —no fix listed
- —upgrade to 6.1.14 or later
- —upgrade to 6.1.14 or later
Is CVE-2024-38819 being exploited?
Likely — EPSS is 93.2%, placing CVE-2024-38819 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (3)
- from 0
- >= 6.1.0, < 6.1.14
- >= 6.1.0, < 6.1.14
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |