#VU11752 Path traversal in Pivotal Spring Framework - CVE-2018-1271
Published: April 11, 2018 / Updated: April 11, 2018
Pivotal Spring Framework
Pivotal
Description
The vulnerability allows a remote unauthenticated attacker to obtain potentially sensitive information and write arbitrary files on the target system.
The weakness exists in the spring-webmvc module due to the improper serving of static resources from a file system on Microsoft Windows systems. A remote attacker can send a malicious request using a crafted URL, trigger directory traversal, overwrite, delete or read potentially sensitive file information.