QID 981241
QID 981241: Java (maven) Security Update for com.sparkjava:spark-core (GHSA-76qr-mmh8-cp8f)
In Spark before 2.7.2, a remote attacker can read unintended static files via various representations of absolute or relative pathnames, as demonstrated by file: URLs and directory traversal sequences. NOTE: this product is unrelated to Ignite Realtime Spark.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-76qr-mmh8-cp8f for updates pertaining to this vulnerability.
Vendor References
- GHSA-76qr-mmh8-cp8f -
github.com/advisories/GHSA-76qr-mmh8-cp8f
CVEs related to QID 981241
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-76qr-mmh8-cp8f | com.sparkjava:spark-core |
|