CVE-2016-9177

HIGH

Spark 2.5 - Path Traversal

Title source: llm

Description

Directory traversal vulnerability in Spark 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

Exploits (4)

nomisec STUB
by dawetmaster · poc
https://github.com/dawetmaster/CVE-2016-9177-perwendel-spark-vulnerable
nomisec STUB
by andikahilmy · poc
https://github.com/andikahilmy/CVE-2016-9177-perwendel-spark-vulnerable
nomisec WRITEUP
by shoucheng3 · poc
https://github.com/shoucheng3/perwendel__spark_CVE-2016-9177_2-5-1

Scores

CVSS v3 7.5
EPSS 0.0551
EPSS Percentile 90.3%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (2)
com.sparkjava/spark-core 0 - 2.5.2Maven
sparkjava/spark < 2.5
Published Nov 04, 2016
Tracked Since Feb 18, 2026