Description
Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not enabled by default in Spring Framework nor Spring Boot, however, when MappingJackson2JsonView is configured in an application, JSONP support is automatically ready to use through the "jsonp" and "callback" JSONP parameters, enabling cross-domain requests.
Published: 2018-06-25
Score: 7.5 High
EPSS: 7.3% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-2635-1 libspring-java security update
EUVD EUVD EUVD-2018-0587 Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not enabled by default in Spring Framework nor Spring Boot, however, when MappingJackson2JsonView is configured in an application, JSONP support is automatically ready to use through the "jsonp" and "callback" JSONP parameters, enabling cross-domain requests.
Github GHSA Github GHSA GHSA-f26x-pr96-vw86 Moderate severity vulnerability that affects org.springframework:spring-core
History

No history.

Subscriptions

Debian Debian Linux
Oracle Agile Product Lifecycle Management Application Testing Suite Communications Network Integrity Communications Online Mediation Controller Communications Services Gatekeeper Communications Unified Inventory Management Endeca Information Discovery Integrator Enterprise Manager Enterprise Manager Ops Center Flexcube Private Banking Healthcare Master Person Index Hospitality Guest Access Insurance Calculation Engine Insurance Rules Palette Micros Lucas Mysql Enterprise Monitor Product Lifecycle Management Retail Advanced Inventory Planning Retail Clearance Optimization Engine Retail Customer Insights Retail Markdown Optimization Retail Predictive Application Server Retail Service Backbone Retail Xstore Point Of Service Utilities Network Management System Weblogic Server
Vmware Spring Framework
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-09-17T02:06:00.434Z

Reserved: 2018-05-14T00:00:00.000Z

Link: CVE-2018-11040

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-06-25T15:29:00.363

Modified: 2024-11-21T03:42:32.900

Link: CVE-2018-11040

cve-icon Redhat

Severity : Low

Publid Date: 2018-06-14T00:00:00Z

Links: CVE-2018-11040 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses