CVE-2017-8039 – org.springframework.webflow:spring-webflow
Package
Manager: maven
Name: org.springframework.webflow:spring-webflow
Vulnerable Version: >=0 <2.4.6
Severity
Level: Medium
CVSS v3.1: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v4.0: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
EPSS: 0.00183 pctl0.40242
Details
Insecure Default Initialization of Resource in Pivotal Spring Web Flow An issue was discovered in Pivotal Spring Web Flow through 2.4.5. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that process form submissions but do not have a sub-element to declare explicit data binding property mappings. NOTE: this issue exists because of an incomplete fix for CVE-2017-4971.
Metadata
Created: 2022-05-13T01:47:15Z
Modified: 2022-06-30T21:13:17Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-q4v9-qjmw-j7vf/GHSA-q4v9-qjmw-j7vf.json
CWE IDs: ["CWE-1188"]
Alternative ID: GHSA-q4v9-qjmw-j7vf
Finding: F164
Auto approve: 1