Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Debian
Subscribe
|
Debian Linux
Subscribe
|
|
Oracle
Subscribe
|
Agile Plm
Subscribe
Application Testing Suite
Subscribe
Communications Diameter Signaling Router
Subscribe
Communications Network Integrity
Subscribe
Communications Online Mediation Controller
Subscribe
Communications Performance Intelligence Center
Subscribe
Communications Services Gatekeeper
Subscribe
Communications Unified Inventory Management
Subscribe
Endeca Information Discovery Integrator
Subscribe
Enterprise Manager Base Platform
Subscribe
Enterprise Manager For Mysql Database
Subscribe
Enterprise Manager Ops Center
Subscribe
Health Sciences Information Manager
Subscribe
Healthcare Master Person Index
Subscribe
Hospitality Guest Access
Subscribe
Insurance Calculation Engine
Subscribe
Insurance Rules Palette
Subscribe
Micros Lucas
Subscribe
Mysql Enterprise Monitor
Subscribe
Primavera P6 Enterprise Project Portfolio Management
Subscribe
Retail Advanced Inventory Planning
Subscribe
Retail Assortment Planning
Subscribe
Retail Clearance Optimization Engine
Subscribe
Retail Customer Insights
Subscribe
Retail Financial Integration
Subscribe
Retail Integration Bus
Subscribe
Retail Markdown Optimization
Subscribe
Retail Predictive Application Server
Subscribe
Retail Xstore Point Of Service
Subscribe
Utilities Network Management System
Subscribe
Weblogic Server
Subscribe
|
|
Vmware
Subscribe
|
Spring Framework
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2635-1 | libspring-java security update |
EUVD |
EUVD-2018-0561 | Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack. |
Github GHSA |
GHSA-9gcm-f4x3-8jpw | Spring Framework Cross Site Tracing (XST) |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-16T22:08:49.057Z
Reserved: 2018-05-14T00:00:00
Link: CVE-2018-11039
No data.
Status : Modified
Published: 2018-06-25T15:29:00.317
Modified: 2024-11-21T03:42:32.633
Link: CVE-2018-11039
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Github GHSA