Description
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rv39-3qh7-9v7w | Improper Input Validation in Spring Framework |
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
Netapp
Subscribe
Oncommand Insight
Subscribe
Snap Creator Framework
Subscribe
Snapcenter
Subscribe
Oracle
Subscribe
Commerce Guided Search
Subscribe
Communications Brm
Subscribe
Communications Design Studio
Subscribe
Communications Session Report Manager
Subscribe
Communications Unified Inventory Management
Subscribe
Endeca Information Discovery Integrator
Subscribe
Enterprise Data Quality
Subscribe
Financial Services Analytical Applications Infrastructure
Subscribe
Flexcube Private Banking
Subscribe
Fusion Middleware
Subscribe
Goldengate Application Adapters
Subscribe
Healthcare Master Person Index
Subscribe
Hyperion Infrastructure Technology
Subscribe
Insurance Policy Administration
Subscribe
Insurance Rules Palette
Subscribe
Mysql Enterprise Monitor
Subscribe
Primavera Gateway
Subscribe
Primavera P6 Enterprise Project Portfolio Management
Subscribe
Retail Assortment Planning
Subscribe
Retail Bulk Data Integration
Subscribe
Retail Customer Engagement
Subscribe
Retail Customer Management And Segmentation Foundation
Subscribe
Retail Financial Integration
Subscribe
Retail Integration Bus
Subscribe
Retail Invoice Matching
Subscribe
Retail Merchandising System
Subscribe
Retail Order Broker
Subscribe
Retail Predictive Application Server
Subscribe
Retail Returns Management
Subscribe
Retail Service Backbone
Subscribe
Retail Xstore Point Of Service
Subscribe
Storagetek Acsls
Subscribe
Storagetek Tape Analytics Sw Tool
Subscribe
Weblogic Server
Subscribe
Redhat
Subscribe
Jboss Fuse
Subscribe
Vmware
Subscribe
Spring Framework
Subscribe
Status: PUBLISHED
Assigner: pivotal
Published:
Updated: 2024-09-17T03:58:43.873Z
Reserved: 2020-01-03T00:00:00.000Z
Link: CVE-2020-5421
No data.
Status : Modified
Published: 2020-09-19T04:15:11.527
Modified: 2024-11-21T05:34:08.303
Link: CVE-2020-5421
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA