← Vulnerability feed

Vulnerability record · CVE-2018-1271 · published 6 April 2018

CVE-2018-1271: Vmware spring framework path traversal vulnerability

Vmware · Spring Framework

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a request using a specially crafted URL that can lead a directory traversal attack.

5.9 CVSS 3.1 Medium EPSS 34% · top 1.6% CWE-22 · Path traversal
5.9CVSS 3.1 base score, v2 4.3
34%EPSS exploitation probability, 30 days
NoNot in CISA KEV
28Affected product versions listed by NVD
22References
17 Jun 2026Last modified by NVD

Description

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a request using a specially crafted URL that can lead a directory traversal attack.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected products

28 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html PatchThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html PatchThird Party Advisory
http://www.securityfocus.com/bid/103699 Third Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2018:1320 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2669 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2939 Third Party Advisory
https://pivotal.io/security/cve-2018-1271 Vendor Advisory
https://www.oracle.com/security-alerts/cpujul2020.html Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html PatchThird Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html PatchThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html PatchThird Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html PatchThird Party Advisory
http://www.securityfocus.com/bid/103699 Third Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2018:1320 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2669 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2939 Third Party Advisory
https://pivotal.io/security/cve-2018-1271 Vendor Advisory
https://www.oracle.com/security-alerts/cpujul2020.html Third Party Advisory
https://www.oracle.com/security-alerts/cpuoct2021.html Third Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html PatchThird Party Advisory
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html PatchThird Party Advisory

Track CVE-2018-1271 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-2555Oracle Coherence T3 deserialization allows unauthenticated remote code executionOracle Coherence (Fusion Middleware) deserializes untrusted data reachable over the T3 protocol, allowing an unauthenticated network attacker to exec…KEVEPSS 97%analysed9.8CVE-2019-2725Oracle WebLogic Server Web Services deserialization RCEOracle WebLogic Server's Web Services subcomponent contains an injection flaw (CWE-74) that allows unauthenticated remote code execution over HTTP. I…KEVEPSS 100%analysed9.8CVE-2017-9841PHPUnit eval-stdin.php remote PHP code executionPHPUnit before 4.8.28 and 5.x before 5.6.3 ships Util/PHP/eval-stdin.php, which evaluates HTTP POST body content as PHP when it begins with a "<?php …KEVEPSS 100%analysed7.8CVE-2021-3156Sudo off-by-one heap overflow allows root privilege escalationSudo before 1.9.5p2 contains an off-by-one error leading to a heap-based buffer overflow. Triggering it via 'sudoedit -s' with a command-line argumen…KEVEPSS 100%analysed6.1CVE-2020-11023jQuery DOM manipulation methods XSS via untrusted HTML option elementsjQuery versions 1.0.3 through before 3.5.0 execute untrusted code when HTML containing <option> elements from untrusted sources is passed to DOM mani…KEVEPSS 85%analysed9.8CVE-2026-46924Oracle application testing suite improper access control vulnerabilityVulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauth…EPSS 0.51%9.8CVE-2026-35290Oracle application testing suite improper access control vulnerabilityVulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauth…EPSS 0.51%9.8CVE-2026-46876Oracle application testing suite improper access control vulnerabilityVulnerability in Oracle Application Testing Suite. The supported version that is affected is 13.3.0.1. Easily exploitable vulnerability allows unauth…EPSS 0.51%

Source: NIST National Vulnerability Database (record CVE-2018-1271), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.