Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GHSA-rhcg-rwhx-qj3j] Improper Limitation of a Pathname to a Restricted Directory in Spring Framework #3736

Conversation

sunSUNQ
Copy link

@sunSUNQ sunSUNQ commented Feb 27, 2024

Updates

  • References
  • Source code location

Comments
Add source code location and patch links related to CVE-2014-3578.

@github-actions github-actions bot changed the base branch from main to sunSUNQ/advisory-improvement-3736 February 27, 2024 03:05
@JonathanLEvans
Copy link

Hi @sunSUNQ, can you explain how these commits relate to the advisory?

@sunSUNQ
Copy link
Author

sunSUNQ commented Mar 6, 2024

Hello, I found that spring-projects/spring-framework#16414 is related to CVE-2014-3578. It mentions [SPR-11793]Currently cleanPath stops at the first semicolon assuming a protocol prefixed path (e.g. "file:core/../core/io/Resource.class"). This is a bit too simple since technically a semicolon is also allowed in a directory name, even if unusual. The current vulnerability is related to the mishandling of the cleanPath class, and it is addressed in spring-projects/spring-framework@f6fddeb, which mentions the fix for SPR-11793. Therefore, I believe this patch is related to the fix for CVE-2014-3578, while the other two patches are fixes on different branches.

@advisory-database advisory-database bot merged commit 08e06e5 into sunSUNQ/advisory-improvement-3736 Mar 18, 2024
2 checks passed
@advisory-database advisory-database bot deleted the sunSUNQ-GHSA-rhcg-rwhx-qj3j branch March 18, 2024 15:05
@advisory-database
Copy link
Contributor

Hi @sunSUNQ! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants