HomeSecuritySpring Framework: Vulnerability allows access to files

Spring Framework: Vulnerability allows access to files

A security vulnerability in the Spring Framework could allow attackers to access any file on the vulnerable system.

Spring Framework Vulnerability

This vulnerability is tracked as CVE-2024-38816 and affects applications that use the WebMvc.fn or WebFlux.fn functional web frameworks. It is a “path traversal” vulnerability and can cause significant damage to systems.

The CVE-2024-38816 in the Spring Framework arises from applications with static resources that use RouterFunctions in combination with FileSystemResource location. This configuration can be exploited by users who create malicious HTTP requests to gain unauthorized access to system files. As a result, hackers can steal important data.

See also: Ivanti: CSA vulnerability used in attacks

However, not all systems using the Spring Framework are vulnerable. Applications using the Spring Security HTTP Firewall or running on Tomcat or Jetty servers are not at risk. These configurations effectively block attempts to exploit the vulnerability.

Which products and which versions of Spring Framework are affected?

The following versions of Spring Framework are affected by the CVE-2024-38816 vulnerability:

  • Spring Framework 5.3.0 – 5.3.39
  • Spring Framework 6.0.0 – 6.0.23
  • Spring Framework 6.1.0 – 6.1.12

It is worth noting that if someone is running an old, unsupported version of the Spring Framework, they are also at risk.

See also: Citrix warns of vulnerabilities in Workspace for Windows

Users are urged to upgrade their systems to the following versions to protect themselves:

Affected Version(s)Fixed VersionAvailability
5.3.x5.3.40Enterprise Support Only
6.0.x6.0.24Enterprise Support Only
6.1.x6.1.13Open Source (OSS)

For users of older, unsupported versions, it is necessary to enable the Spring Security Firewall or switch to Tomcat or Jetty as the web server.

In addition to updating the Spring Framework, it is also important for organizations to take other precautions to prevent potential attacks. This includes implementing strict access controls and regularly monitoring system activity for any suspicious behavior. It is also recommended to conduct a thorough audit of all applications that use the affected versions of the framework and ensure that appropriate security measures are in place .

Hackers are constantly looking for vulnerabilities in popular frameworks and software, making it imperative for developers to remain vigilant and address any security.

See also: Windows vulnerability exploited by Void Banshee in zero-day attacks

This incident also highlights the need for strong collaboration between developers, security teams, and IT departments to ensure that comprehensive security. By working together, organizations can strengthen their defenses against potential attacks and minimize the impact of any security breaches.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: gbhackers.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS