CVE-2017-4971
Summary
| CVE | CVE-2017-4971 |
|---|---|
| State | PUBLISHED |
| Assigner | dell |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-06-13 06:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that process form submissions but do not have a sub-element to declare explicit data binding property mappings. |
Risk And Classification
Primary CVSS: v3.0 5.9 MEDIUM from [email protected]
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Problem Types: CWE-1188 | Data Binding Expression Vulnerability in Spring Web Flow
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 5.9 | MEDIUM | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |
| 2.0 | [email protected] | Primary | 4.3 | AV:N/AC:M/Au:N/C:N/I:P/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
HighPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
HighAvailability
NoneCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Pivotal | Spring Web Flow | 2.4.0 | All | All | All |
| Application | Pivotal | Spring Web Flow | 2.4.1 | All | All | All |
| Application | Pivotal | Spring Web Flow | 2.4.2 | All | All | All |
| Application | Pivotal | Spring Web Flow | 2.4.4 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Na | Spring Web Flow | affected Spring Web Flow | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| [SWF-1700] CVE-2017-4971: Avoid use of SpEL parser for empty value expressions - Spring JIRA | af854a3a-2127-422b-91ae-364da2661108 | jira.spring.io | Issue Tracking, Patch |
| CVE-2017-4971: Data Binding Expression Vulnerability in Spring Web Flow | Security | Pivotal | af854a3a-2127-422b-91ae-364da2661108 | pivotal.io | Mitigation, Patch, Vendor Advisory |
| Pivotal Spring Web Flow CVE-2017-4971 Security Bypass Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377315 Spring Web Flow Data Binding Expression Vulnerability