CVE-2024-38819

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Dec 19, 2024
Updated: Jan 10, 2025
CWE ID 22

Summary

CVE-2024-38819: This vulnerability affects applications using Spring WebMvc.fn or WebFlux.fn for serving static resources. An attacker can exploit path traversal attacks by crafting malicious HTTP requests, potentially gaining unauthorized access to any file on the file system that is accessible to the Spring application process. This could lead to information disclosure or even execution of arbitrary code. Developers are advised to apply the necessary patches or workarounds to prevent such attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Vmware Spring Framework

Affected Vendors

  • VMware Inc.