[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

251951

 
 

909

 
 

196667

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2018-1272 -- libspring-java

ID: oval:org.secpod.oval:def:2001379Date: (C)2019-06-06   (M)2022-06-23
Class: VULNERABILITYFamily: unix




Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application receives input from a remote client, and then uses that input to make a multipart request to another server , it can be exposed to an attack, where an extra multipart is inserted in the content of the request from server A, causing server B to use the wrong value for a part it expects. This could to lead privilege escalation, for example, if the part content represents a username or user roles.

Platform:
Debian 9.x
Product:
libspring-core-java
Reference:
CVE-2018-1272
CVE    1
CVE-2018-1272
CPE    2
cpe:/a:libspring-java:libspring-core-java
cpe:/o:debian:debian_linux:9.x

© SecPod Technologies