{"api_version":"1","generated_at":"2026-07-24T04:56:53+00:00","cve":"CVE-2014-3625","urls":{"html":"https://cve.report/CVE-2014-3625","api":"https://cve.report/api/cve/CVE-2014-3625.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-3625","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-3625"},"summary":{"title":"CVE-2014-3625","description":"Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.","state":"PUBLISHED","assigner":"redhat","published_at":"2014-11-20 17:50:00","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-22","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://lists.debian.org/debian-lts-announce/2019/07/msg00012.html","name":"https://lists.debian.org/debian-lts-announce/2019/07/msg00012.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[SECURITY] [DLA 1853-1] libspring-java security update","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.pivotal.io/security/cve-2014-3625","name":"http://www.pivotal.io/security/cve-2014-3625","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"CVE-2014-3625 | Pivotal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-0236.html","name":"http://rhn.redhat.com/errata/RHSA-2015-0236.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://jira.spring.io/browse/SPR-12354","name":"https://jira.spring.io/browse/SPR-12354","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"[SPR-12354] Directory traversal with static resource handling (CVE-2014-3625) - Spring JIRA","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://rhn.redhat.com/errata/RHSA-2015-0720.html","name":"http://rhn.redhat.com/errata/RHSA-2015-0720.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-3625","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-3625","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"3625","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"pivotal_software","cpe5":"spring_framework","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2014","cve_id":"3625","vulnerable":"1","versionEndIncluding":"3.1.4","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"pivotal_software","cpe5":"spring_framework","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T10:50:17.833Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"RHSA-2015:0720","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2015-0720.html"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.pivotal.io/security/cve-2014-3625"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://jira.spring.io/browse/SPR-12354"},{"name":"RHSA-2015:0236","tags":["vendor-advisory","x_refsource_REDHAT","x_transferred"],"url":"http://rhn.redhat.com/errata/RHSA-2015-0236.html"},{"name":"[debian-lts-announce] 20190713 [SECURITY] [DLA 1853-1] libspring-java security update","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"https://lists.debian.org/debian-lts-announce/2019/07/msg00012.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-11-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2019-07-13T23:06:02.000Z","orgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","shortName":"redhat"},"references":[{"name":"RHSA-2015:0720","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2015-0720.html"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.pivotal.io/security/cve-2014-3625"},{"tags":["x_refsource_CONFIRM"],"url":"https://jira.spring.io/browse/SPR-12354"},{"name":"RHSA-2015:0236","tags":["vendor-advisory","x_refsource_REDHAT"],"url":"http://rhn.redhat.com/errata/RHSA-2015-0236.html"},{"name":"[debian-lts-announce] 20190713 [SECURITY] [DLA 1853-1] libspring-java security update","tags":["mailing-list","x_refsource_MLIST"],"url":"https://lists.debian.org/debian-lts-announce/2019/07/msg00012.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secalert@redhat.com","ID":"CVE-2014-3625","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"RHSA-2015:0720","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2015-0720.html"},{"name":"http://www.pivotal.io/security/cve-2014-3625","refsource":"CONFIRM","url":"http://www.pivotal.io/security/cve-2014-3625"},{"name":"https://jira.spring.io/browse/SPR-12354","refsource":"CONFIRM","url":"https://jira.spring.io/browse/SPR-12354"},{"name":"RHSA-2015:0236","refsource":"REDHAT","url":"http://rhn.redhat.com/errata/RHSA-2015-0236.html"},{"name":"[debian-lts-announce] 20190713 [SECURITY] [DLA 1853-1] libspring-java security update","refsource":"MLIST","url":"https://lists.debian.org/debian-lts-announce/2019/07/msg00012.html"}]}}}},"cveMetadata":{"assignerOrgId":"53f830b8-0a3f-465b-8143-3b8a9948e749","assignerShortName":"redhat","cveId":"CVE-2014-3625","datePublished":"2014-11-20T17:00:00.000Z","dateReserved":"2014-05-14T00:00:00.000Z","dateUpdated":"2024-08-06T10:50:17.833Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-11-20 17:50:00","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-22","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:pivotal_software:spring_framework:*:*:*:*:*:*:*:*","versionStartIncluding":"3.1.0","versionEndIncluding":"3.1.4","matchCriteriaId":"FF9AB837-EAF8-45AC-9758-CC4357B54C66"},{"vulnerable":true,"criteria":"cpe:2.3:a:pivotal_software:spring_framework:*:*:*:*:*:*:*:*","versionStartIncluding":"3.2.0","versionEndExcluding":"3.2.12","matchCriteriaId":"BF486CA6-B388-4E08-B752-5B1D92881377"},{"vulnerable":true,"criteria":"cpe:2.3:a:pivotal_software:spring_framework:*:*:*:*:*:*:*:*","versionStartIncluding":"4.0.0","versionEndExcluding":"4.0.8","matchCriteriaId":"85B0B579-8E34-4C21-80E1-461D7A797075"},{"vulnerable":true,"criteria":"cpe:2.3:a:pivotal_software:spring_framework:*:*:*:*:*:*:*:*","versionStartIncluding":"4.1.0","versionEndExcluding":"4.1.2","matchCriteriaId":"C0F7D07C-183C-4F53-AD9E-3A7E5820E6D7"},{"vulnerable":true,"criteria":"cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*","versionStartIncluding":"3.0.4","versionEndIncluding":"3.0.7","matchCriteriaId":"1DFC0C4B-DA2F-4F49-9132-44E89A3BD6B9"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"3625","Ordinal":"1","Title":"CVE-2014-3625","CVE":"CVE-2014-3625","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"3625","Ordinal":"1","NoteData":"Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.","Type":"Description","Title":"CVE-2014-3625"},{"CveYear":"2014","CveId":"3625","Ordinal":"2","NoteData":"2014-11-20","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"3625","Ordinal":"3","NoteData":"2019-07-13","Type":"Other","Title":"Modified"}]}}}