Skip to main content
Solved

Spring Framework < 5.3.40 / 6.0.x < 6.0.24 / 6.1.x < 6.1.13 Path Traversal (CVE-2024-38816)


Forum|alt.badge.img+1

Hi, is there a reference document to remediate this reported vulnerability?

 Path              : C:\Program Files\Commvault\ContentStore\MessageQueue\lib\optional\spring-core-5.3.39.jar
  Installed version : 5.3.39
  Fixed version     : 5.3.40
 

Thanks

Best answer by Damian Andre

Hey ​@Roderick Serbony,

Not sure what version you are on, but I see in an existing cast that 11.36.46 or higher should ship with a newer spring core (6.1.4). There are several reported CVE’s we’ve analyzed that do not impact our software (we’re not using those specific features of the framework and therefore are not vulnerable).

I’ll try to see if I can get information on if a newer version is included in other releases outside of 11.36.

View original
Did this answer your question?

4 replies

Damian Andre
Vaulter
Forum|alt.badge.img+23
  • Vaulter
  • 1297 replies
  • Answer
  • March 28, 2025

Hey ​@Roderick Serbony,

Not sure what version you are on, but I see in an existing cast that 11.36.46 or higher should ship with a newer spring core (6.1.4). There are several reported CVE’s we’ve analyzed that do not impact our software (we’re not using those specific features of the framework and therefore are not vulnerable).

I’ll try to see if I can get information on if a newer version is included in other releases outside of 11.36.


Forum|alt.badge.img+1

Hi Damian,

Thank you for your prompt response. We are running on version 11.32.89, will check with support if we can safely upgrade to that version.


Damian Andre
Vaulter
Forum|alt.badge.img+23

Our team has been looking into the vulnerabilities related to the spring framework. The functions we use in that framework do not match any active CVE’s (including this one). So while this one comes up on scanners, its not possible to exploit as we don't use those parts of the framework.

 


Forum|alt.badge.img+1

@Damian Andre; we have deleted the files related to the reported vulnerability “spring-xxxxx.jar” and after server reboot, the Message queue “IntelliSnap for NetApp Messaging Queue” doesn’t start.

But the backup is completing successful. We are still monitoring the backup, till we receive the advice from CommVault support to proceed with the upgrade.


Reply


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings