5.0
MEDIUM
CVE-2014-3578
Pivotal Spring Framework Remote File Inclusion
Description

Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.

INFO

Published Date :

Feb. 19, 2015, 8:59 p.m.

Last Modified :

April 12, 2025, 10:46 a.m.

Remotely Exploitable :

Yes !

Impact Score :

2.9

Exploitability Score :

10.0
Public PoC/Exploit Available at Github

CVE-2014-3578 has a 1 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

Affected Products

The following products are affected by CVE-2014-3578 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Pivotal_software spring_framework
References to Advisories, Solutions, and Tools

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

一款针对Spring框架的漏洞扫描及漏洞利用图形化工具

Updated: 1 week, 1 day ago
172 stars 7 fork 7 watcher
Born at : March 11, 2024, 6:04 a.m. This repo has been linked 8 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2014-3578 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2014-3578 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • CVE Modified by af854a3a-2127-422b-91ae-364da2661108

    Nov. 21, 2024

    Action Type Old Value New Value
    Added Reference http://jvn.jp/en/jp/JVN49154900/index.html
    Added Reference http://jvndb.jvn.jp/jvndb/JVNDB-2014-000054
    Added Reference http://pivotal.io/security/cve-2014-3578
    Added Reference http://rhn.redhat.com/errata/RHSA-2015-0720.html
    Added Reference http://www.securityfocus.com/bid/68042
    Added Reference https://bugzilla.redhat.com/show_bug.cgi?id=1131882
    Added Reference https://lists.debian.org/debian-lts-announce/2019/07/msg00012.html
    Added Reference https://rhn.redhat.com/errata/RHSA-2015-0234.html
    Added Reference https://rhn.redhat.com/errata/RHSA-2015-0235.html
  • CVE Modified by [email protected]

    May. 14, 2024

    Action Type Old Value New Value
  • CVE Modified by [email protected]

    Jul. 14, 2019

    Action Type Old Value New Value
    Added Reference https://lists.debian.org/debian-lts-announce/2019/07/msg00012.html [No Types Assigned]
  • Modified Analysis by [email protected]

    Mar. 21, 2019

    Action Type Old Value New Value
    Changed Reference Type https://rhn.redhat.com/errata/RHSA-2015-0234.html No Types Assigned https://rhn.redhat.com/errata/RHSA-2015-0234.html Third Party Advisory
    Changed Reference Type http://jvn.jp/en/jp/JVN49154900/index.html Vendor Advisory http://jvn.jp/en/jp/JVN49154900/index.html Third Party Advisory, VDB Entry
    Changed Reference Type https://rhn.redhat.com/errata/RHSA-2015-0235.html No Types Assigned https://rhn.redhat.com/errata/RHSA-2015-0235.html Third Party Advisory
    Changed Reference Type http://rhn.redhat.com/errata/RHSA-2015-0720.html No Types Assigned http://rhn.redhat.com/errata/RHSA-2015-0720.html Third Party Advisory
    Changed Reference Type http://www.securityfocus.com/bid/68042 No Types Assigned http://www.securityfocus.com/bid/68042 Third Party Advisory, VDB Entry
    Changed Reference Type https://bugzilla.redhat.com/show_bug.cgi?id=1131882 No Types Assigned https://bugzilla.redhat.com/show_bug.cgi?id=1131882 Issue Tracking, Third Party Advisory
    Changed Reference Type http://jvndb.jvn.jp/jvndb/JVNDB-2014-000054 Vendor Advisory http://jvndb.jvn.jp/jvndb/JVNDB-2014-000054 Third Party Advisory, VDB Entry
    Changed CPE Configuration OR *cpe:2.3:a:pivotal:spring_framework:3.0.4:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.0.5:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.0.6:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.0.7:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.1.0:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.1.1:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.1.2:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.1.3:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.1.4:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.2.0:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.2.1:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.2.2:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.2.3:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.2.4:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.2.5:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.2.6:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.2.7:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.2.8:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.2.10:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.2.11:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:4.0.0:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:4.0.1:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:4.0.2:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:4.0.3:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:4.0.4:*:*:*:*:*:*:* OR *cpe:2.3:a:pivotal_software:spring_framework:*:*:*:*:*:*:*:* versions from (including) 3.2.0 up to (excluding) 3.2.9 *cpe:2.3:a:pivotal_software:spring_framework:*:*:*:*:*:*:*:* versions from (including) 4.0.0 up to (excluding) 4.0.5
  • CVE Modified by [email protected]

    Nov. 28, 2016

    Action Type Old Value New Value
    Added Reference http://www.securityfocus.com/bid/68042 [No Types Assigned]
  • CVE Modified by [email protected]

    Mar. 28, 2015

    Action Type Old Value New Value
    Added Reference http://rhn.redhat.com/errata/RHSA-2015-0720.html
  • Modified Analysis by [email protected]

    Feb. 20, 2015

    Action Type Old Value New Value
    Added CPE Configuration Configuration 1 OR *cpe:2.3:a:pivotal:spring_framework:4.0.4:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:4.0.3:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:4.0.2:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:4.0.1:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:4.0.0:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.2.8:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.2.7:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.2.6:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.2.5:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.2.4:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.2.3:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.2.2:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.2.11:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.2.10:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.2.1:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.2.0:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.1.4:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.1.3:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.1.2:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.1.1:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.1.0:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.0.7:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.0.6:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.0.5:*:*:*:*:*:*:* *cpe:2.3:a:pivotal:spring_framework:3.0.4:*:*:*:*:*:*:*
    Added CVSS V2 (AV:N/AC:L/Au:N/C:P/I:N/A:N)
    Changed Reference Type http://jvndb.jvn.jp/jvndb/JVNDB-2014-000054 No Types Assigned http://jvndb.jvn.jp/jvndb/JVNDB-2014-000054 Advisory
    Changed Reference Type http://jvn.jp/en/jp/JVN49154900/index.html No Types Assigned http://jvn.jp/en/jp/JVN49154900/index.html Advisory
    Changed Reference Type http://pivotal.io/security/cve-2014-3578 No Types Assigned http://pivotal.io/security/cve-2014-3578 Advisory
    Added CWE CWE-22
  • Initial Analysis by [email protected]

    Feb. 20, 2015

    Action Type Old Value New Value
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2014-3578 is associated with the following CWEs:

Exploit Prediction

EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days.

5.83 }} 0.06%

score

0.89999

percentile

CVSS2 - Vulnerability Scoring System
Access Vector
Access Complexity
Authentication
Confidentiality
Integrity
Availability
© cvefeed.io
Latest DB Update: May. 15, 2025 1:43