Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.

Project Subscriptions

Vendors Products
Debian Linux Subscribe
Agile Plm Subscribe
Application Testing Suite Subscribe
Communications Diameter Signaling Router Subscribe
Communications Network Integrity Subscribe
Communications Online Mediation Controller Subscribe
Communications Performance Intelligence Center Subscribe
Communications Services Gatekeeper Subscribe
Communications Unified Inventory Management Subscribe
Endeca Information Discovery Integrator Subscribe
Enterprise Manager Base Platform Subscribe
Enterprise Manager For Mysql Database Subscribe
Enterprise Manager Ops Center Subscribe
Health Sciences Information Manager Subscribe
Healthcare Master Person Index Subscribe
Hospitality Guest Access Subscribe
Insurance Calculation Engine Subscribe
Insurance Rules Palette Subscribe
Micros Lucas Subscribe
Mysql Enterprise Monitor Subscribe
Primavera P6 Enterprise Project Portfolio Management Subscribe
Retail Advanced Inventory Planning Subscribe
Retail Assortment Planning Subscribe
Retail Clearance Optimization Engine Subscribe
Retail Customer Insights Subscribe
Retail Financial Integration Subscribe
Retail Integration Bus Subscribe
Retail Markdown Optimization Subscribe
Retail Predictive Application Server Subscribe
Retail Xstore Point Of Service Subscribe
Utilities Network Management System Subscribe
Weblogic Server Subscribe
Spring Framework Subscribe
Advisories
Source ID Title
Debian DLA Debian DLA DLA-2635-1 libspring-java security update
EUVD EUVD EUVD-2018-0561 Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.
Github GHSA Github GHSA GHSA-9gcm-f4x3-8jpw Spring Framework Cross Site Tracing (XST)
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-09-16T22:08:49.057Z

Reserved: 2018-05-14T00:00:00

Link: CVE-2018-11039

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-06-25T15:29:00.317

Modified: 2024-11-21T03:42:32.633

Link: CVE-2018-11039

cve-icon Redhat

Severity : Low

Publid Date: 2018-06-14T00:00:00Z

Links: CVE-2018-11039 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses