Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-5421

Опубликовано: 17 сент. 2020
Источник: redhat
CVSS3: 6.5
EPSS Средний

Описание

In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.

In Spring Framework, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.

Отчет

This issue does not affect the version of SpringFramework (embedded in rhvm-dependencies) shipped with Red Hat Virtualization, as it does not provide support for spring-web. In Red Hat Gluster Storage 3, SpringFramework (embedded in rhvm-dependencies) was shipped as a part of Red Hat Gluster Storage Console that is no longer supported for use with Red Hat Gluster Storage 3.5. However, spring-web is not included in the shipped version of SpringFramework.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss BRMS 5springframeworkOut of support scope
Red Hat JBoss Data Virtualization 6springframeworkOut of support scope
Red Hat JBoss Fuse 6springframeworkOut of support scope
Red Hat JBoss Fuse Service Works 6springframeworkOut of support scope
Red Hat JBoss SOA Platform 5springframeworkOut of support scope
Red Hat Storage 3rhevm-dependenciesNot affected
Red Hat Virtualization 4rhvm-dependenciesNot affected
Red Hat Fuse 7.9springframeworkFixedRHSA-2021:314011.08.2021

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=1881158springframework: RFD protection bypass via jsessionid

EPSS

Процентиль: 98%
0.59873
Средний

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
почти 5 лет назад

In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.

CVSS3: 6.5
nvd
почти 5 лет назад

In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.

CVSS3: 6.5
debian
почти 5 лет назад

In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5. ...

CVSS3: 6.5
github
больше 4 лет назад

Improper Input Validation in Spring Framework

CVSS3: 8.7
fstec
почти 5 лет назад

Уязвимость программной платформы Spring Framework, связанная с небезопасным управлением привилегиями, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации

EPSS

Процентиль: 98%
0.59873
Средний

6.5 Medium

CVSS3