Pivotal Spring Web Flow CVE-2017-8039 Incomplete Fix Security Bypass Vulnerability
BID:100849
Info
Pivotal Spring Web Flow CVE-2017-8039 Incomplete Fix Security Bypass Vulnerability
| Bugtraq ID: | 100849 |
| Class: | Design Error |
| CVE: |
CVE-2017-8039 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 15 2017 12:00AM |
| Updated: | Sep 15 2017 12:00AM |
| Credit: | he1renyagao |
| Vulnerable: |
Pivotal Spring Web Flow 2.4.5 Pivotal Spring Web Flow 2.4.4 Pivotal Spring Web Flow 2.4.3 Pivotal Spring Web Flow 2.4.2 Pivotal Spring Web Flow 2.4.1 Pivotal Spring Web Flow 2.4 |
| Not Vulnerable: |
Pivotal Spring Web Flow 2.4.6 |
Discussion
Pivotal Spring Web Flow CVE-2017-8039 Incomplete Fix Security Bypass Vulnerability
Pivotal Spring Web Flow is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass security restrictions and perform unauthorized actions. This may aid in further attacks.
Spring Web Flow versions 2.4.0 through 2.4.5 are vulnerable.
NOTE: This issue is the result of an incomplete fix for the issue described in BID 98785 (Pivotal Spring Web Flow CVE-2017-4971 Security Bypass Vulnerability).
Pivotal Spring Web Flow is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass security restrictions and perform unauthorized actions. This may aid in further attacks.
Spring Web Flow versions 2.4.0 through 2.4.5 are vulnerable.
NOTE: This issue is the result of an incomplete fix for the issue described in BID 98785 (Pivotal Spring Web Flow CVE-2017-4971 Security Bypass Vulnerability).
Exploit / POC
Pivotal Spring Web Flow CVE-2017-8039 Incomplete Fix Security Bypass Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Pivotal Spring Web Flow CVE-2017-8039 Incomplete Fix Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Pivotal Spring Web Flow CVE-2017-8039 Incomplete Fix Security Bypass Vulnerability
References:
References:
- CVE-2017-8039: Validate data binding expression in AbstractMvcView (Spring Web Flow)
- Pivotal Homepage (Pivotal)
- SWF-1711: AbstractMvcView validates default binding expression (Github)
- SWF-1711: Check default binding expressions (Github)
- SWF-1711: Ignore (invalid) default binding expressions (Github)
- CVE-2017-8039: Data Binding Expression Vulnerability in Spring Web Flow (Pivotal)