CVE-2024-38819: Path Traversal
Applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn are vulnerable to path traversal attacks. An attacker can craft malicious HTTP requests and obtain any file on the file system that is also accessible to the process in which the Spring application is running.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-38819?
CVE-2024-38819 is classified as a high-severity vulnerability due to its potential for allowing attackers to perform path traversal attacks.
How do I fix CVE-2024-38819?
To fix CVE-2024-38819, upgrade to Spring Web MVC or Spring WebFlux version 6.1.14 or later.
What types of applications are affected by CVE-2024-38819?
CVE-2024-38819 affects applications serving static resources through Spring's WebMvc.fn or WebFlux.fn frameworks.
Can CVE-2024-38819 lead to data exposure?
Yes, CVE-2024-38819 can lead to unauthorized data exposure by allowing attackers to access arbitrary files on the server.
Which versions of Spring are impacted by CVE-2024-38819?
Versions of Spring Web MVC and Spring WebFlux from 5.0.0 up to 6.0.23 and also 6.1.0 to 6.1.14 are affected by CVE-2024-38819.