CVE-2018-11039
⚪ Do wiadomości
Luka w Spring Framework umożliwia atak XST przez zmianę metody HTTP w aplikacjach webowych.
CVSS: źródło nieustalone · szczegóły: D1
CVSS
5.9
EPSS
2.8%
Exploit
none
Vendor
oracle
Opis źródłowy (NVD)
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.
xss
Status patcha: nieustalony
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 5.9 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS · ocena nieustalona | 2.8% |
| Opublikowano (NVD) | 2018-06-25 15:29:00 UTC |
| Ostatnia modyfikacja (NVD) | 2026-10-08 22:16:44 UTC |
Referencje
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html ([email protected]) [Patch, Third Party Advisory]
- http://www.securityfocus.com/bid/107984 ([email protected]) [Broken Link, Third Party Advisory, VDB Entry]
- https://lists.debian.org/debian-lts-announce/2021/04/msg00022.html ([email protected]) [Mailing List, Third Party Advisory]
- https://pivotal.io/security/cve-2018-11039 ([email protected]) [Mitigation, Vendor Advisory]
- https://www.oracle.com/security-alerts/cpujan2020.html ([email protected]) [Patch, Third Party Advisory]
- https://www.oracle.com/security-alerts/cpujul2020.html ([email protected]) [Patch, Third Party Advisory]
- https://www.oracle.com/security-alerts/cpuoct2021.html ([email protected]) [Patch, Third Party Advisory]
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html ([email protected]) [Patch, Third Party Advisory]
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html ([email protected]) [Patch, Third Party Advisory]
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html ([email protected]) [Patch, Third Party Advisory]