← Back to browse · API

CVE-2024-38819

Severity
HIGH
CVSS
7.5
EPSS
0.54862
Risk score
49.2
CISA KEV
No
PoC
No
Published
2024-12-19
Modified
2025-01-10
First seen
2026-08-07
Aliases
EUVD-2024-3583, GHSA-G5VR-RGQM-VF78
Products
VMware:Spring Framework Spring Framework 5.3.0 - 5.3.40, 6.0.0 - 6.0.24, 6.1.0 - 6.1.13
Sources
euvd EUVD-2024-3583

Description

Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.

References