Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.springframework:spring-core(Maven) | 3.0.0 | 3.2.9 | N/A |
| org.springframework:spring-core(Maven) | 4.0.0 | 4.0.5 | N/A |
CVSS Metrics