CVE-2024-38819
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Dec 19, 2024
Updated: Jan 10, 2025
CWE ID 22
Summary
CVE-2024-38819: This vulnerability affects applications using Spring WebMvc.fn or WebFlux.fn for serving static resources. An attacker can exploit path traversal attacks by crafting malicious HTTP requests, potentially gaining unauthorized access to any file on the file system that is accessible to the Spring application process. This could lead to information disclosure or even execution of arbitrary code. Developers are advised to apply the necessary patches or workarounds to prevent such attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Vmware Spring Framework
Affected Vendors
- VMware Inc.