An issue was discovered in Pivotal Spring Web Flow through 2.4.5. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., …
中危 CVSS 5.9
摘要
An issue was discovered in Pivotal Spring Web Flow through 2.4.5. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that process form submissions but do not have a sub-element to declare explicit data binding property mappings. NOTE: this issue exists because of an incomplete fix for CVE-2017-4971.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- http://www.securityfocus.com/bid/100849 Third Party Advisory
- https://pivotal.io/security/cve-2017-8039 Issue Tracking
- http://www.securityfocus.com/bid/100849 Third Party Advisory
- https://pivotal.io/security/cve-2017-8039 Issue Tracking
时间线
- nvd_ingest NVD