Description
A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected products
- Spring / Spring Framework7.0.0 – 7.0.8
- Spring / Spring Framework6.2.0 – 6.2.19
- Spring / Spring Framework6.1.0 – 6.1.28
- Spring / Spring Framework6.0.0 – 6.0.30
- Spring / Spring Framework5.3.0 – 5.3.49
- Spring / Spring Framework0 – 5.2.25.RELEASE
- VMware / Spring Framework5.2.26
References
Updated 5m ago · 8 sources