Description
UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected products
- Spring / Spring Framework7.0.0 – 7.0.8
- Spring / Spring Framework6.2.0 – 6.2.19
- VMware / Spring Framework6.2.0 – 6.2.20
References
Updated 5m ago · 8 sources