An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., …
中危 CVSS 5.9
摘要
An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that process form submissions but do not have a sub-element to declare explicit data binding property mappings.
中文摘要建设中,暂以英文摘要呈现(DR-003 v2)。
深度研判
该漏洞尚未生成深度研判报告(DR-003 v2 AI pipeline 建设中)。
受影响产品
- :
数据来源
- NVD DATABASE
原始链接
- http://www.securityfocus.com/bid/98785 Third Party Advisory
- https://jira.spring.io/browse/SWF-1700 Issue Tracking
- https://pivotal.io/security/cve-2017-4971 Mitigation
- http://www.securityfocus.com/bid/98785 Third Party Advisory
- https://jira.spring.io/browse/SWF-1700 Issue Tracking
- https://pivotal.io/security/cve-2017-4971 Mitigation
时间线
- nvd_ingest NVD