Описание
Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
A flaw was found in Spring MVC and WebFlux applications, components of the Spring Framework. This vulnerability allows a remote, unauthenticated attacker to perform Multipart request smuggling attacks. Such an attack can lead to a low integrity impact, potentially enabling the attacker to bypass security controls or modify data.
Отчет
This Moderate-impact flaw in Spring MVC and WebFlux applications allows remote, unauthenticated attackers to conduct Multipart request smuggling. This can lead to bypassing security controls or modifying data, affecting the integrity of applications utilizing these Spring Framework components.
Меры по смягчению последствий
Users of affected versions should upgrade to the corresponding fixed version.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Developer Tools and Services | jenkins | Fix deferred | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel8 | Fix deferred | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel9 | Fix deferred | ||
| OpenShift Developer Tools and Services | spring-web | Fix deferred | ||
| Red Hat build of Apache Camel 4 for Quarkus 3 | spring-web | Fix deferred | ||
| Red Hat build of Apache Camel - HawtIO 4 | spring-web | Fix deferred | ||
| Red Hat Data Grid 8 | spring-web | Fix deferred | ||
| Red Hat Enterprise Linux 7 | xbean | Fix deferred | ||
| Red Hat Enterprise Linux 8 | javapackages-tools:201801/xbean | Fix deferred | ||
| Red Hat Enterprise Linux 8 | pki-core:10.6/resteasy | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Spring MVC and WebFlux applications are vulnerable to Multipart reques ...
Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
EPSS
5.3 Medium
CVSS3