Description
Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not enabled by default in Spring Framework nor Spring Boot, however, when MappingJackson2JsonView is configured in an application, JSONP support is automatically ready to use through the "jsonp" and "callback" JSONP parameters, enabling cross-domain requests.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2635-1 | libspring-java security update |
EUVD |
EUVD-2018-0587 | Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not enabled by default in Spring Framework nor Spring Boot, however, when MappingJackson2JsonView is configured in an application, JSONP support is automatically ready to use through the "jsonp" and "callback" JSONP parameters, enabling cross-domain requests. |
Github GHSA |
GHSA-f26x-pr96-vw86 | Moderate severity vulnerability that affects org.springframework:spring-core |
References
History
No history.
Subscriptions
Debian
Subscribe
Debian Linux
Subscribe
Oracle
Subscribe
Agile Product Lifecycle Management
Subscribe
Application Testing Suite
Subscribe
Communications Network Integrity
Subscribe
Communications Online Mediation Controller
Subscribe
Communications Services Gatekeeper
Subscribe
Communications Unified Inventory Management
Subscribe
Endeca Information Discovery Integrator
Subscribe
Enterprise Manager
Subscribe
Enterprise Manager Ops Center
Subscribe
Flexcube Private Banking
Subscribe
Healthcare Master Person Index
Subscribe
Hospitality Guest Access
Subscribe
Insurance Calculation Engine
Subscribe
Insurance Rules Palette
Subscribe
Micros Lucas
Subscribe
Mysql Enterprise Monitor
Subscribe
Product Lifecycle Management
Subscribe
Retail Advanced Inventory Planning
Subscribe
Retail Clearance Optimization Engine
Subscribe
Retail Customer Insights
Subscribe
Retail Markdown Optimization
Subscribe
Retail Predictive Application Server
Subscribe
Retail Service Backbone
Subscribe
Retail Xstore Point Of Service
Subscribe
Utilities Network Management System
Subscribe
Weblogic Server
Subscribe
Vmware
Subscribe
Spring Framework
Subscribe
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-17T02:06:00.434Z
Reserved: 2018-05-14T00:00:00.000Z
Link: CVE-2018-11040
No data.
Status : Modified
Published: 2018-06-25T15:29:00.363
Modified: 2024-11-21T03:42:32.900
Link: CVE-2018-11040
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Github GHSA