Closed mend-bolt-for-github[bot] closed 3 years ago
Spring Framework Parent
Path to dependency file: struts-2.3.20/plugins/portlet/pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/3.0.5.RELEASE/spring-webmvc-3.0.5.RELEASE.jar
Dependency Hierarchy: - spring-webmvc-portlet-3.0.5.RELEASE.jar (Root Library) - :x: **spring-webmvc-3.0.5.RELEASE.jar** (Vulnerable Library)
Found in HEAD commit: 1d3a9da2b49a075b9122e05e19a483fc66b5aaf4
Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.
Publish Date: 2014-11-20
URL: CVE-2014-3625
Base Score Metrics not available
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2014-3625
Release Date: 2014-11-20
Fix Resolution: 3.2.12,4.0.8,4.1.2
:information_source: This issue was automatically closed by WhiteSource because it is a duplicate of an existing issue: #83
CVE-2014-3625 - Medium Severity Vulnerability
Vulnerable Library - spring-webmvc-3.0.5.RELEASE.jar
Spring Framework Parent
Path to dependency file: struts-2.3.20/plugins/portlet/pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/spring-webmvc/3.0.5.RELEASE/spring-webmvc-3.0.5.RELEASE.jar
Dependency Hierarchy: - spring-webmvc-portlet-3.0.5.RELEASE.jar (Root Library) - :x: **spring-webmvc-3.0.5.RELEASE.jar** (Vulnerable Library)
Found in HEAD commit: 1d3a9da2b49a075b9122e05e19a483fc66b5aaf4
Vulnerability Details
Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.
Publish Date: 2014-11-20
URL: CVE-2014-3625
CVSS 2 Score Details (5.0)
Base Score Metrics not available
Suggested Fix
Type: Upgrade version
Origin: https://nvd.nist.gov/vuln/detail/CVE-2014-3625
Release Date: 2014-11-20
Fix Resolution: 3.2.12,4.0.8,4.1.2