Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including…
Medium CVSS 5.9
Summary
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
- :
- :
Sources
- NVD DATABASE
Original Links
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html Patch
- http://www.securityfocus.com/bid/107984 Broken Link
- https://lists.debian.org/debian-lts-announce/2021/04/msg00022.html Mailing List
- https://pivotal.io/security/cve-2018-11039 Mitigation
- https://www.oracle.com/security-alerts/cpujan2020.html Patch
- https://www.oracle.com/security-alerts/cpujul2020.html Patch
- https://www.oracle.com/security-alerts/cpuoct2021.html Patch
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html Patch
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html Patch
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html Patch
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html Patch
- http://www.securityfocus.com/bid/107984 Broken Link
- https://lists.debian.org/debian-lts-announce/2021/04/msg00022.html Mailing List
- https://pivotal.io/security/cve-2018-11039 Mitigation
- https://www.oracle.com/security-alerts/cpujan2020.html Patch
- https://www.oracle.com/security-alerts/cpujul2020.html Patch
- https://www.oracle.com/security-alerts/cpuoct2021.html Patch
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html Patch
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html Patch
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html Patch
Timeline
- nvd_ingest NVD