VDB

DEBIAN-CVE-2024-38819

DEBIAN-CVE-2024-38819 PUBLISHED CVSS 7.5 HIGH

Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
Debian:12libspring-java4.3.30-4, 4.3.30-3, 4.3.30-4
Debian:14libspring-java0, 0, 4.3.30-3
Debian:11libspring-java4.3.30-1, 0, 4.3.30-2
Debian:13libspring-java0, 4.3.30-4, 4.3.30-3

Timeline

  • Dec 19, 2024 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›