CVE-2017-4971
Summary
| CVE | CVE-2017-4971 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-06-13 06:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that process form submissions but do not have a sub-element to declare explicit data binding property mappings. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SWF-1700] CVE-2017-4971: Avoid use of SpEL parser for empty value expressions - Spring JIRA |
CONFIRM |
jira.spring.io |
Issue Tracking, Patch |
| CVE-2017-4971: Data Binding Expression Vulnerability in Spring Web Flow | Security | Pivotal |
CONFIRM |
pivotal.io |
Mitigation, Patch, Vendor Advisory |
| Pivotal Spring Web Flow CVE-2017-4971 Security Bypass Vulnerability |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377315 Spring Web Flow Data Binding Expression Vulnerability