We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-46822

Unauthenticated Arbitrary File Read via Absolute Path



Description

OsamaTaher/Java-springboot-codebase is a collection of Java and Spring Boot code snippets, applications, and projects. Prior to commit c835c6f7799eacada4c0fc77e0816f250af01ad2, insufficient path traversal mechanisms make absolute path traversal possible. This vulnerability allows unauthorized access to sensitive internal files. Commit c835c6f7799eacada4c0fc77e0816f250af01ad2 contains a patch for the issue.

Reserved 2025-04-30 | Published 2025-05-21 | Updated 2025-05-21 | Assigner GitHub_M


HIGH: 7.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P

Problem types

CWE-36: Absolute Path Traversal

Product status

< c835c6f7799eacada4c0fc77e0816f250af01ad2
affected

References

github.com/...debase/security/advisories/GHSA-q6mm-cm37-w637

github.com/...ommit/c835c6f7799eacada4c0fc77e0816f250af01ad2

cve.org (CVE-2025-46822)

nvd.nist.gov (CVE-2025-46822)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-46822

Support options

Helpdesk Chat, Email, Knowledgebase