Path traversal in Spring Framework - CVE-2024-38816

 

Path traversal in Spring Framework - CVE-2024-38816

Published: September 12, 2024 / Updated: December 4, 2024


Vulnerability identifier: #VU97224
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-38816
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences in applications serving static resources through the functional web frameworks WebMvc.fn or WebFlux.fn. A remote attacker can send a specially crafted HTTP request and read arbitrary files on the system.

Specifically, an application is vulnerable when both of the following are true:

  • the web application uses RouterFunctions</code> to serve static resources</li><li>resource handling is explicitly configured with a <code>FileSystemResource location


Affected software

Spring Framework
IBM Cloud Pak for Security
IBM Watson Knowledge Catalog in Cloud Pak for Data
Crowd Data Center
Confluence Data Center
Bitbucket Data Center
IBM Maximo Application Suite - AI Broker
Oracle Communications Cloud Native Core DBTier
IBM Observability with Instana
IBM Process Mining
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Dell Secure Connect Gateway
IBM Sterling Connect:Direct Web Services
IBM Cloud Pak for Business Automation
QRadar Suite
watsonx.data
DB2 Data Management Console
Knowledge Catalog Premium Cartridge
DevOps Solution Workbench
CICS Transaction Gateway Desktop Edition
CICS Transaction Gateway for Multiplatforms
Business Automation Insights
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component
Maximo Application Suite - Monitor Component
Crowd Server
Confluence Server
Bitbucket Server
Library Support for Spring
Red Hat Camel for Spring Boot
IBM InfoSphere Information Server
IBM Security Guardium

How to mitigate CVE-2024-38816

Install update from vendor's website.

Spring Framework - addressed in versions 5.3.40, 6.0.24, 6.1.13
QRadar Suite - update to 1.10.27.0
watsonx.data - update to 2.1
DB2 Data Management Console - update to 3.1.13.2
IBM Watson Knowledge Catalog in Cloud Pak for Data - addressed in versions 4.8.8, 4.8.9, 5.1.1, 5.1.2, 5.1.3
Knowledge Catalog Premium Cartridge - update to 5.2
Crowd Data Center - update to 5.3.6
Crowd Server - update to 5.3.6
Confluence Data Center - addressed in versions 7.19.29, 8.5.17, 8.9.8, 9.1.1
Confluence Server - addressed in versions 7.19.29, 8.5.17, 8.9.8, 9.1.1
Bitbucket Data Center - addressed in versions 8.9.21, 8.19.11
Bitbucket Server - addressed in versions 8.9.21, 8.19.11
IBM Maximo Application Suite - AI Broker - update to 9.0.3
Business Automation Insights - update to 24.0.0.0.2
IBM Observability with Instana - update to 286
IBM Process Mining - update to 1.15.0 IF004
Library Support for Spring - update to 2.7.29
Red Hat Camel for Spring Boot - update to 4.4.3
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.1
watsonx Orchestrate with watsonx Assistant Cartridge - Assistant Builder Component - update to 5.2.1
Dell Secure Connect Gateway - update to 5.26.00.18
IBM Sterling Connect:Direct Web Services - addressed in versions 6.1.0.26, 6.2.0.25, 6.3.0.11
Maximo Application Suite - Monitor Component - addressed in versions 8.10.15, 9.0.4
IBM InfoSphere Information Server - update to 11.7.1 Fix Pack 5
IBM Security Guardium - update to 12.0p30
IBM Cloud Pak for Business Automation - addressed in versions 21.0.3-IF039, 24.0.0-IF004, 24.0.1

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins