Sparkjava is a lightweight Java web framework focused on building microservices and REST APIs, with its vulnerability profile centered on the core Spark framework product. The observed exposure involves path-traversal issues in request handling and resource access, a characteristic concern in web frameworks where insufficient pathname validation can allow directory escape attacks. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sparkjava over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-9159MEDIUM In Spark before 2.7.2, a remote attacker can read unintended static files via various representations of absolute or relative pathnames, as demonstrated by file: URLs and directory | Mar 31, 2018 | 5.3 | 21 | NO | NO |
CVE-2016-9177HIGH Directory traversal vulnerability in Spark 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. | Nov 4, 2016 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sparkjava.
Media articles that mention a CVE ID that affects a product developed by Sparkjava — matched by CVE ID, not by vendor name.