
In-depth analysis of CVE-2024-38819, a Spring WebFlux file traversal vulnerability, with code-level breakdown, PoC, and mitigation strategies including filters and IPS rules.
File-Traversal (Path Traversal) vulnerability allows an attacker to bypass file system permissions in a web application and access arbitrary files, and is a type of attack designated as CWE-22.
Spring WebFlux is a module introduced in Spring 5 that supports reactive programming, enabling asynchronous non-blocking application development. WebFlux.fn provides functional endpoint routing, supporting concise and flexible routing configuration using lambda expressions.
CVE-2024-38819 occurs in applications using WebFlux.fn and WebMVC.fn. This document aims to examine how the vulnerability occurs in WebFlux by reviewing the code flow and to explore corresponding countermeasures.
[Figure 1] FileApplication.java
[Figure 1] shows Spring WebFlux serving all requests coming to /static/** from the server's C:/file directory by finding them. Here, during the
[Figure 2] PathResourceLookupFunction.class - apply
[Figure 2] PathResourceLookupFunction - apply checks whether a given path points to a valid resource in Spring WebFlux and returns the
[Figure 3] PathResourceLookupFunction.class - isInvalidPath
Looking at [Figure 3] PathResourceLookupFunction - isInvalidPath, there is a condition StringUtils.cleanPath(path).contains("../"). When a request like
[Figure 4] StringUtils.class - cleanPath
Looking at [Figure 4] StringUtils.class - cleanPath, StringUtils.cleanPath(path) removes TOP_PATH("..") and then puts the path into pathElements, making top 0. Therefore,
[Figure 5] PathResourceLookupFunction.class - apply - 2
[Figure 6] PathResourceLookupFunction.class - isResourceUnderLocation
The path passed in [Figure 5] is validated again through cleanPath in [Figure 6] via the cleanPath call in isResourceUnderLocation. The path passed in [Figure 5] is C:/file../Windows/System32/drivers/etc/hosts.
[Figure 7] StringUtils.class - cleanPath -2
Through the code in [Figure 7], the prefix becomes C:/ , and the path is changed to /Windows/System32/drivers/etc/hosts via [Figure 4]. The final return isCurrently, the test was conducted on Windows with C:/file, but this case is very dangerous when combined with symbolic links on Linux.
(When setting ../../ twice, it behaves normally; vulnerability occurs only with a single ../ )

Attack combined with symbolic link on Linux server
public RouterFunction<ServerResponse> staticResourceRouter() {
return RouterFunctions.resources("/static/**", new FileSystemResource("/app/static/"));
}
Add symbolic link: ln -s /static /app/static/link, then attack

We have reviewed the flow of File Traversal (CVE-2024-38819) in the Spring Webflux environment. Since this attack method steals server information, countermeasures are important. We propose updating to the latest version, creating additional validation logic, and blocking via IPS.