Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.springframework.security/spring-security-core
  4. ›
  5. CVE-2016-9879

CVE-2016-9879: Encoded "/" in path variables

January 6, 2017 (updated May 14, 2024)

This package does not consider URL path parameters when processing security constraints.Users of IBM WebSphere Application Server 8.5.x are known to be affected. Users of other containers that implement the Servlet specification may be affected.

References

  • pivotal.io/security/cve-2016-9879

Code Behaviors & Features

Detect and mitigate CVE-2016-9879 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions from 3.0.0.RELEASE up to 3.2.9.release, all versions starting from 4.1-alpha0 up to 4.1.3.release, all versions starting from 4.2-alpha0 up to 4.2.0.release

Fixed versions

  • 3.2.10.RELEASE
  • 4.1.4.RELEASE
  • 4.2.1.RELEASE

Solution

Upgrade to versions 3.2.10.RELEASE, 4.1.4.RELEASE, 4.2.1.RELEASE or above.

Impact 7.5 HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Learn more about CVSS

Weakness

  • CWE-417

Source file

maven/org.springframework.security/spring-security-core/CVE-2016-9879.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:16:15 +0000.