Security controls bypass or absence In libspring-java
Description
Improper Input Validation in Spring Framework In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Package | Affected version | Patched versions |
|---|---|---|---|
debian 13 | 4.3.30-1 | ||
maven | 4.3.29.release, 5.0.19.release, 5.1.18.release, 5.2.9.release | ||
maven | 4.3.29.release, 5.0.19.release, 5.1.18.release, 5.2.9.release | ||
maven | 5.0.19.release, 5.1.18.release, 5.2.9.release | ||
maven | 4.3.29.release, 5.0.19.release, 5.1.18.release, 5.2.9.release | ||
debian 14 | 4.3.30-1 | ||
maven | 5.2.9, 5.1.18, 5.0.19, 4.3.29 | ||
maven | 4.3.29.release, 5.0.19.release, 5.1.18.release, 5.2.9.release | ||
debian 12 | 4.3.30-1 | ||
debian 11 | 4.3.30-1 |
1-10 of 11
10
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3. 4. 5. 6. 7. 8. 9. 10. 11. 12. 13. 14. 15. 16. 17. 18. 19. 20. 21. 22. 23. 24. 25.