Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-41254

Опубликовано: 16 окт. 2025
Источник: redhat
CVSS3: 4.3
EPSS Низкий

Описание

STOMP over WebSocket applications may be vulnerable to a security bypass that allows an attacker to send unauthorized messages. Affected Spring Products and VersionsSpring Framework:

  • 6.2.0 - 6.2.11
  • 6.1.0 - 6.1.23
  • 6.0.x - 6.0.29
  • 5.3.0 - 5.3.45
  • Older, unsupported versions are also affected. MitigationUsers of affected versions should upgrade to the corresponding fixed version. Affected version(s)Fix versionAvailability6.2.x6.2.12OSS6.1.x6.1.24 Commercial https://enterprise.spring.io/ 6.0.xN/A Out of support https://spring.io/projects/spring-framework#support 5.3.x5.3.46 Commercial https://enterprise.spring.io/ No further mitigation steps are necessary. CreditThis vulnerability was discovered and responsibly reported by Jannis Kaiser.

    A CSRF flaw has been discovered in the Spring Framework. Usage of the STOMP messaging protocol over a WebSocket based application may be vulnerable to a security bypass that allows an attacker to send unauthorized messages.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftspring-coreFix deferred
Red Hat AMQ Broker 7spring-coreFix deferred
Red Hat AMQ Clientsspring-coreFix deferred
Red Hat build of Apache Camel for Spring Boot 4spring-coreFix deferred
Red Hat build of Apache Camel for Spring Boot 4spring-core-testFix deferred
Red Hat build of Apache Camel - HawtIO 4spring-coreFix deferred
Red Hat build of OptaPlanner 8spring-coreFix deferred
Red Hat Data Grid 8spring-coreFix deferred
Red Hat Enterprise Linux 8log4j:2/log4jFix deferred
Red Hat Enterprise Linux 8pki-core:10.6/resteasyFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-352
https://bugzilla.redhat.com/show_bug.cgi?id=2404437org.springframework/spring-core: Spring Framework STOMP CSRF Vulnerability

EPSS

Процентиль: 19%
0.0006
Низкий

4.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
6 месяцев назад

STOMP over WebSocket applications may be vulnerable to a security bypass that allows an attacker to send unauthorized messages. Affected Spring Products and VersionsSpring Framework: * 6.2.0 - 6.2.11 * 6.1.0 - 6.1.23 * 6.0.x - 6.0.29 * 5.3.0 - 5.3.45 * Older, unsupported versions are also affected. MitigationUsers of affected versions should upgrade to the corresponding fixed version. Affected version(s)Fix versionAvailability6.2.x6.2.12OSS6.1.x6.1.24 Commercial https://enterprise.spring.io/ 6.0.xN/A Out of support https://spring.io/projects/spring-framework#support 5.3.x5.3.46 Commercial https://enterprise.spring.io/ No further mitigation steps are necessary. CreditThis vulnerability was discovered and responsibly reported by Jannis Kaiser.

CVSS3: 4.3
nvd
6 месяцев назад

STOMP over WebSocket applications may be vulnerable to a security bypass that allows an attacker to send unauthorized messages. Affected Spring Products and VersionsSpring Framework: * 6.2.0 - 6.2.11 * 6.1.0 - 6.1.23 * 6.0.x - 6.0.29 * 5.3.0 - 5.3.45 * Older, unsupported versions are also affected. MitigationUsers of affected versions should upgrade to the corresponding fixed version. Affected version(s)Fix versionAvailability6.2.x6.2.12OSS6.1.x6.1.24 Commercial https://enterprise.spring.io/ 6.0.xN/A Out of support https://spring.io/projects/spring-framework#support 5.3.x5.3.46 Commercial https://enterprise.spring.io/ No further mitigation steps are necessary. CreditThis vulnerability was discovered and responsibly reported by Jannis Kaiser.

CVSS3: 4.3
debian
6 месяцев назад

STOMP over WebSocket applications may be vulnerable to a security bypa ...

CVSS3: 4.3
github
6 месяцев назад

Spring Framework STOMP over WebSocket applications may allow attackers to send unauthorized messages

EPSS

Процентиль: 19%
0.0006
Низкий

4.3 Medium

CVSS3