漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Spring Framework Improper Path Limitation with Script View Templates
Vulnerability Description
Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Vulnerability Type
N/A
Vulnerability Title
Spring Framework 安全漏洞
Vulnerability Description
Spring Framework是Spring开源的一款应用开发框架。 Spring Framework 7.0.5及之前版本、6.2.16及之前版本、6.1.25及之前版本和5.3.46及之前版本存在安全漏洞,该漏洞源于使用Java脚本引擎模板视图可能导致脚本模板视图配置位置之外的文件内容泄露。
CVSS Information
N/A
Vulnerability Type
N/A