PT-2026-64810 · Perwendel · Sparkjava
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
perwendel spark versions prior to 2.9.5
Description
A flaw in the SparkJava component allows remote attackers to trigger symlink following. This occurs within the
staticFiles.externalLocation function located in the src/main/java/spark/resource/ExternalResourceHandler.jav file. Symlink following is a condition where the application follows a symbolic link to access files outside the intended directory.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
As a temporary workaround, restrict the use of the
staticFiles.externalLocation function to minimize the risk of exploitation.Exploit
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sparkjava