Home

Description

OsamaTaher/Java-springboot-codebase is a collection of Java and Spring Boot code snippets, applications, and projects. Prior to commit c835c6f7799eacada4c0fc77e0816f250af01ad2, insufficient path traversal mechanisms make absolute path traversal possible. This vulnerability allows unauthorized access to sensitive internal files. Commit c835c6f7799eacada4c0fc77e0816f250af01ad2 contains a patch for the issue.

PUBLISHED Reserved 2025-04-30 | Published 2025-05-21 | Updated 2025-05-21 | Assigner GitHub_M




HIGH: 7.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P

Problem types

CWE-36: Absolute Path Traversal

Product status

< c835c6f7799eacada4c0fc77e0816f250af01ad2
affected

References

github.com/...debase/security/advisories/GHSA-q6mm-cm37-w637 exploit

github.com/...debase/security/advisories/GHSA-q6mm-cm37-w637

github.com/...ommit/c835c6f7799eacada4c0fc77e0816f250af01ad2

cve.org (CVE-2025-46822)

nvd.nist.gov (CVE-2025-46822)

Download JSON