Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1571050 - (CVE-2018-1271) CVE-2018-1271 spring-framework: Directory traversal vulnerability with static resources on Windows filesystems
CVE-2018-1271 spring-framework: Directory traversal vulnerability with static...
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20180405,repor...
: Security
Depends On:
Blocks: 1571053
  Show dependency treegraph
 
Reported: 2018-04-23 22:38 EDT by Sam Fowler
Modified: 2018-10-24 21:36 EDT (History)
77 users (show)

See Also:
Fixed In Version: springframework 5.05, springframework 4.3.15
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2018:1320 None None None 2018-05-03 13:07 EDT
Red Hat Product Errata RHSA-2018:2669 None None None 2018-09-11 03:55 EDT
Red Hat Product Errata RHSA-2018:2939 None None None 2018-10-17 15:30 EDT

  None (edit)
Description Sam Fowler 2018-04-23 22:38:14 EDT
Spring Framework versions 5.0 to 5.0.4, 4.3 to 4.3.14, and older unsupported versions allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a request using a specially crafted URL that can lead a directory traversal attack.

This vulnerability does not affect applications that use versions of Spring Security patched for CVE-2018-1199. 


External Reference:

https://pivotal.io/security/cve-2018-1271
Comment 3 errata-xmlrpc 2018-05-03 13:06:58 EDT
This issue has been addressed in the following products:

  Red Hat Openshift Application Runtimes

Via RHSA-2018:1320 https://access.redhat.com/errata/RHSA-2018:1320
Comment 5 errata-xmlrpc 2018-09-11 03:54:47 EDT
This issue has been addressed in the following products:

  Red Hat JBoss Fuse

Via RHSA-2018:2669 https://access.redhat.com/errata/RHSA-2018:2669
Comment 6 errata-xmlrpc 2018-10-17 15:29:59 EDT
This issue has been addressed in the following products:

  Red Hat Fuse Intergration Services 2.0 based on Fuse 6.3 R8

Via RHSA-2018:2939 https://access.redhat.com/errata/RHSA-2018:2939

Note You need to log in before you can comment on or make changes to this bug.