Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-11039

Опубликовано: 14 июн. 2018
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.

Отчет

From an OpenDaylight perspective, whilst the shipped versions of Open Dayight ship artifacts which fall within the affected versions ("older unsupported versions"), this flaw only has impact in the presence of an existing XSS flaw. Given there are currently no XSS flaws in the shipped versions, and the libraries themselves are not used in a vulnerable way, no package update to mitigate this flaw for Open Daylight is required. The package rhevm-dependencies does not include the spring-webmvc component, where this vulnerability exists.

Меры по смягчению последствий

According to the upstream advisory, this attack applies to applications that allow the application server to handle HTTP TRACE requests, and use the HiddenHttpMethodFilter. Note that in the HiddenHttpMethodFilter is enabled by default in Spring Boot.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7springframeworkNot affected
Red Hat JBoss BRMS 5springframeworkOut of support scope
Red Hat JBoss Data Virtualization 6springframeworkOut of support scope
Red Hat JBoss Fuse 6springframeworkOut of support scope
Red Hat JBoss Fuse Service Works 6springframeworkOut of support scope
Red Hat JBoss SOA Platform 5springframeworkOut of support scope
Red Hat OpenStack Platform 10 (Newton)opendaylightWill not fix
Red Hat OpenStack Platform 11 (Ocata)opendaylightWill not fix
Red Hat OpenStack Platform 12 (Pike)opendaylightWill not fix
Red Hat OpenStack Platform 13 (Queens)opendaylightWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-648
https://bugzilla.redhat.com/show_bug.cgi?id=1591929springframework: Cross Site Tracing (XST) if vulnerable to XSS

EPSS

Процентиль: 86%
0.02919
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
почти 7 лет назад

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.

CVSS3: 5.9
nvd
почти 7 лет назад

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.

CVSS3: 5.9
debian
почти 7 лет назад

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior ...

CVSS3: 5.9
github
больше 6 лет назад

Spring Framework Cross Site Tracing (XST)

CVSS3: 5.9
fstec
почти 7 лет назад

Уязвимость реализации механизма HiddenHttpMethodFilter программной платформы Spring Framework, позволяющая нарушителю осуществить межсайтовую сценарную атаку

EPSS

Процентиль: 86%
0.02919
Низкий

3.7 Low

CVSS3