Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9ggw-87m9-9gfc

Опубликовано: 11 июн. 2026
Источник: github
Github: Прошло ревью
CVSS3: 6.4

Описание

Spring Web Flow has Data Binding Vulnerability with Unified EL Parser

Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions.

Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.

Пакеты

Наименование

org.springframework.webflow:spring-webflow

maven
Затронутые версииВерсия исправления

= 4.0.0

4.0.1

Наименование

org.springframework.webflow:spring-webflow

maven
Затронутые версииВерсия исправления

>= 3.0.0, < 3.0.2

3.0.2

Наименование

org.springframework.webflow:spring-webflow

maven
Затронутые версииВерсия исправления

<= 2.5.1

Отсутствует

EPSS

Процентиль: 13%
0.00225
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-917

Связанные уязвимости

CVSS3: 6.4
nvd
2 месяца назад

Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.

EPSS

Процентиль: 13%
0.00225
Низкий

6.4 Medium

CVSS3

Дефекты

CWE-917