CVE-2018-11039
Summary
| CVE | CVE-2018-11039 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-06-25 15:29:00 UTC |
| Updated | 2022-06-23 16:30:00 UTC |
| Description | Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Oracle Critical Patch Update Advisory - July 2020 | MISC | www.oracle.com | |
| Oracle Critical Patch Update Advisory - October 2021 | MISC | www.oracle.com | |
| [SECURITY] [DLA 2635-1] libspring-java security update | MLIST | lists.debian.org | |
| Spring Framework CVE-2018-11039 Cross Site Scripting Vulnerability | BID | www.securityfocus.com | |
| Oracle Critical Patch Update - January 2019 | CONFIRM | www.oracle.com | |
| Oracle Critical Patch Update - July 2019 | MISC | www.oracle.com | |
| CVE-2018-11039: Cross Site Tracing (XST) with Spring Framework | Security | Pivotal | CONFIRM | pivotal.io | Mitigation, Vendor Advisory |
| CPU Oct 2018 | CONFIRM | www.oracle.com | |
| Oracle Critical Patch Update Advisory - January 2020 | MISC | www.oracle.com | |
| Oracle Critical Patch Update Advisory - April 2019 | MISC | www.oracle.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.