Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-8039


An issue was discovered in Pivotal Spring Web Flow through 2.4.5. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that process form submissions but do not have a sub-element to declare explicit data binding property mappings. NOTE: this issue exists because of an incomplete fix for CVE-2017-4971.


Published

2017-11-27T10:29:00.847

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 5.9 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.6

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-1188

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application pivotal spring_web_flow 2.4.0 Yes
Application pivotal spring_web_flow 2.4.1 Yes
Application pivotal spring_web_flow 2.4.2 Yes
Application pivotal spring_web_flow 2.4.4 Yes
Application pivotal spring_web_flow 2.4.5 Yes

References