spring-webmvc is vulnerable to directory traversal attack. The vulnerability exists due to the improper sanitization of the path values which allows valid Windows files to be served as static resources. This vulnerability only affects spring-webmvc running on Windows which allows serving files with the file: locator, does not use Spring Security with versions patched for CVE-2018-1199, and use Tomcat/WildFly as the server.
Veracode Software Composition Analysis
file:
locator, does not use Spring Security with versions patched forCVE-2018-1199
, and use Tomcat/WildFly as the server.Links: