QID 981206
QID 981206: Java (maven) Security Update for com.sparkjava:spark-core (GHSA-89gc-6cw6-4vch)
Directory traversal vulnerability in Spark 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-89gc-6cw6-4vch for updates pertaining to this vulnerability.
Vendor References
- GHSA-89gc-6cw6-4vch -
github.com/advisories/GHSA-89gc-6cw6-4vch
CVEs related to QID 981206
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-89gc-6cw6-4vch | com.sparkjava:spark-core |
|