CVE-2017-8039
Summary
| CVE | CVE-2017-8039 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-11-27 10:29:00 UTC |
| Updated | 2019-10-03 00:03:00 UTC |
| Description | An issue was discovered in Pivotal Spring Web Flow through 2.4.5. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that process form submissions but do not have a sub-element to declare explicit data binding property mappings. NOTE: this issue exists because of an incomplete fix for CVE-2017-4971. |
Risk And Classification
Problem Types: CWE-1188
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Pivotal | Spring Web Flow | 2.4.0 | All | All | All |
| Application | Pivotal | Spring Web Flow | 2.4.1 | All | All | All |
| Application | Pivotal | Spring Web Flow | 2.4.2 | All | All | All |
| Application | Pivotal | Spring Web Flow | 2.4.4 | All | All | All |
| Application | Pivotal | Spring Web Flow | 2.4.5 | All | All | All |
| Application | Pivotal | Spring Web Flow | 2.4.0 | All | All | All |
| Application | Pivotal | Spring Web Flow | 2.4.1 | All | All | All |
| Application | Pivotal | Spring Web Flow | 2.4.2 | All | All | All |
| Application | Pivotal | Spring Web Flow | 2.4.4 | All | All | All |
| Application | Pivotal | Spring Web Flow | 2.4.5 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Pivotal Spring Web Flow CVE-2017-8039 Incomplete Fix Security Bypass Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE-2017-8039: Data Binding Expression Vulnerability in Spring Web Flow | Security | Pivotal | CONFIRM | pivotal.io | Issue Tracking, Mitigation, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.