{"id":68314,"date":"2025-08-18T14:31:43","date_gmt":"2025-08-18T11:01:43","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2025-41242-apache-tomcat-and-eclipse-jetty-spring-framework-mvc-path-traversal-vulnerability\/"},"modified":"2025-08-18T14:31:43","modified_gmt":"2025-08-18T11:01:43","slug":"cve-2025-41242-apache-tomcat-and-eclipse-jetty-spring-framework-mvc-path-traversal-vulnerability","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2025-41242-apache-tomcat-and-eclipse-jetty-spring-framework-mvc-path-traversal-vulnerability\/","title":{"rendered":"CVE-2025-41242 &#8211; Apache Tomcat and Eclipse Jetty Spring Framework MVC Path Traversal Vulnerability"},"content":{"rendered":"<p><strong>CVE ID : <\/strong>CVE-2025-41242<br \/>\n<br \/>\n<strong>Published : <\/strong> Aug. 18, 2025, 9:15 a.m. | 55\u00a0minutes ago<br \/>\n<br \/>\n<strong>Description : <\/strong>Spring Framework MVC applications can be vulnerable to a \u201cPath Traversal Vulnerability\u201d when deployed on a non-compliant Servlet container.<\/p>\n<p>An application can be vulnerable when all the following are true:<\/p>\n<p>  *  the application is deployed as a WAR or with an embedded Servlet container<br \/>\n  *  the Servlet container  does not reject suspicious sequences https:\/\/jakarta.ee\/specifications\/servlet\/6.1\/jakarta-servlet-spec-6.1.html#uri-path-canonicalization<br \/>\n  *  the application  serves static resources https:\/\/docs.spring.io\/spring-framework\/reference\/web\/webmvc\/mvc-config\/static-resources.html#page-title \u00a0with Spring resource handling<\/p>\n<p>We have verified that applications deployed on Apache Tomcat or Eclipse Jetty are not vulnerable, as long as default security features are not disabled in the configuration. Because we cannot check exploits against all Servlet containers and configuration variants, we strongly recommend upgrading your application.<br \/>\n<br \/>\n<strong>Severity:<\/strong> 5.9 | MEDIUM<br \/>\n<br \/>\nVisit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID : CVE-2025-41242 Published : Aug. 18, 2025, 9:15 a.m. | 55\u00a0minutes ago Description : Spring Framework MVC applications can be vulnerable to a \u201cPath Traversal Vulnerability\u201d when deployed on a non-compliant Servlet container. An application can be vulnerable when all the following are true: * the application is deployed as a WAR or &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-68314","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/68314","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=68314"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/68314\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=68314"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=68314"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=68314"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}