Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-1272

Опубликовано: 06 апр. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6
CVSS3: 7.5

Описание

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote client, and then uses that input to make a multipart request to another server (server B), it can be exposed to an attack, where an extra multipart is inserted in the content of the request from server A, causing server B to use the wrong value for a part it expects. This could to lead privilege escalation, for example, if the part content represents a username or user roles.

РелизСтатусПримечание
artful

ignored

end of life
bionic

not-affected

4.3.19-1
cosmic

not-affected

4.3.19-1
devel

not-affected

4.3.19-1
disco

not-affected

4.3.19-1
esm-apps/bionic

not-affected

4.3.19-1
esm-apps/xenial

not-affected

code not present
esm-infra-legacy/trusty

not-affected

code not present
precise/esm

DNE

trusty

ignored

end of standard support

Показывать по

EPSS

Процентиль: 82%
0.01872
Низкий

6 Medium

CVSS2

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.3
redhat
около 7 лет назад

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote client, and then uses that input to make a multipart request to another server (server B), it can be exposed to an attack, where an extra multipart is inserted in the content of the request from server A, causing server B to use the wrong value for a part it expects. This could to lead privilege escalation, for example, if the part content represents a username or user roles.

CVSS3: 7.5
nvd
около 7 лет назад

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote client, and then uses that input to make a multipart request to another server (server B), it can be exposed to an attack, where an extra multipart is inserted in the content of the request from server A, causing server B to use the wrong value for a part it expects. This could to lead privilege escalation, for example, if the part content represents a username or user roles.

CVSS3: 7.5
debian
около 7 лет назад

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior t ...

CVSS3: 7.5
github
больше 6 лет назад

Possible privilege escalation in org.springframework:spring-core

EPSS

Процентиль: 82%
0.01872
Низкий

6 Medium

CVSS2

7.5 High

CVSS3