Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Atlassian Bitbucket | — | Upgrade Atlassian Bitbucket to the latest version | Nov 18, 2025 | Nov 18, 2025 |
| Atlassian Jira | — | Upgrade to the latest version of Atlassian JIRA | May 15, 2025 | Mar 18, 2025 |
| Debian | — | No solution exists | May 15, 2025 | Dec 19, 2024 |
| Oracle Ebs | — | Apply the jan-2025 Critical Patch Update (CPU) (Patch ) for Oracle E-Business Suite | Feb 27, 2026 | Jan 14, 2025 |
| Oracle Weblogic | — | Apply the Patch Set Update (PSU) 38132265 for version 14.1.1.0.0.Apply the Patch Set Update (PSU) 38156117 for version 12.2.1.4.0.Apply the Patch Set Update (PSU) 38130086 for version 14.1.2.0.0. | Jul 16, 2025 | Dec 19, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub