A security vulnerability in the Spring Framework could allow attackers to access any file on the vulnerable system.

This vulnerability is tracked as CVE-2024-38816 and affects applications that use the WebMvc.fn or WebFlux.fn functional web frameworks. It is a “path traversal” vulnerability and can cause significant damage to systems.
The CVE-2024-38816 in the Spring Framework arises from applications with static resources that use RouterFunctions in combination with FileSystemResource location. This configuration can be exploited by users who create malicious HTTP requests to gain unauthorized access to system files. As a result, hackers can steal important data.
See also: Ivanti: CSA vulnerability used in attacks
However, not all systems using the Spring Framework are vulnerable. Applications using the Spring Security HTTP Firewall or running on Tomcat or Jetty servers are not at risk. These configurations effectively block attempts to exploit the vulnerability.
Which products and which versions of Spring Framework are affected?
The following versions of Spring Framework are affected by the CVE-2024-38816 vulnerability:
- Spring Framework 5.3.0 – 5.3.39
- Spring Framework 6.0.0 – 6.0.23
- Spring Framework 6.1.0 – 6.1.12
It is worth noting that if someone is running an old, unsupported version of the Spring Framework, they are also at risk.
See also: Citrix warns of vulnerabilities in Workspace for Windows
Users are urged to upgrade their systems to the following versions to protect themselves:
| Affected Version(s) | Fixed Version | Availability |
| 5.3.x | 5.3.40 | Enterprise Support Only |
| 6.0.x | 6.0.24 | Enterprise Support Only |
| 6.1.x | 6.1.13 | Open Source (OSS) |
For users of older, unsupported versions, it is necessary to enable the Spring Security Firewall or switch to Tomcat or Jetty as the web server.
In addition to updating the Spring Framework, it is also important for organizations to take other precautions to prevent potential attacks. This includes implementing strict access controls and regularly monitoring system activity for any suspicious behavior. It is also recommended to conduct a thorough audit of all applications that use the affected versions of the framework and ensure that appropriate security measures are in place .
Hackers are constantly looking for vulnerabilities in popular frameworks and software, making it imperative for developers to remain vigilant and address any security.
See also: Windows vulnerability exploited by Void Banshee in zero-day attacks
This incident also highlights the need for strong collaboration between developers, security teams, and IT departments to ensure that comprehensive security. By working together, organizations can strengthen their defenses against potential attacks and minimize the impact of any security breaches.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: gbhackers.com
