logo

Spring Product Security Update Advisory (CVE-2024-38816)

ID: 68340e88-a0b6-5c3c-8b4f-a771fd4fad74

STIX ID: report--68340e88-a0b6-5c3c-8b4f-a771fd4fad74

Feed Name: ASEC

Threat Score
50/100

Date Published: 2024-09-18

Date Updated: 2026-04-26

Author: ATCP

...
...

An advisory for CVE-2024-38816 describes a path traversal vulnerability in Spring Framework functional web frameworks (WebMvc.fn/WebFlux.fn) when static resources are served using FileSystemResource. Affected Spring Framework versions are listed and patched releases are provided (5.3.40, 6.0.24, 6.1.13); users are advised to update and references to the NVD and Spring security advisory are included.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.