2.9.4
11 years ago
2 years ago
Known vulnerabilities in the com.sparkjava:spark-core package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
com.sparkjava:spark-core is a web framework for java. Affected versions of this package are vulnerable to Information Exposure. A remote attacker can read unintended static files via various epresentations of absolute or relative pathnames. NOTE: this product is unrelated to Ignite Realtime Spark. How to fix Information Exposure? Upgrade | [,2.7.2) |
com.sparkjava:spark-core is a web framework for java. Affected versions of this package are vulnerable to Directory Traversal. A remote attacker could use this flaw to read arbitrary files that are accessible to the user running the process. How to fix Directory Traversal? Upgrade | [,2.7.2) |
| [,2.5.2) |