Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-274r-p6v6-fhh4

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Spring Batch Admin vulnerable to Cross-site request forgery (CSRF) in the file upload functionality

Cross-site request forgery (CSRF) vulnerability in the Spring Batch Admin before 1.3.0 allows remote attackers to hijack the authentication of unspecified victims and submit arbitrary requests, such as exploiting the file upload vulnerability.

Пакеты

Наименование

org.springframework.batch:spring-batch-admin-manager

maven
Затронутые версииВерсия исправления

< 1.3.0.RELEASE

1.3.0.RELEASE

EPSS

Процентиль: 38%
0.00162
Низкий

8.8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
nvd
около 8 лет назад

Cross-site request forgery (CSRF) vulnerability in the Spring Batch Admin before 1.3.0 allows remote attackers to hijack the authentication of unspecified victims and submit arbitrary requests, such as exploiting the file upload vulnerability.

EPSS

Процентиль: 38%
0.00162
Низкий

8.8 High

CVSS3

Дефекты

CWE-352