CVE-2017-4971
Insecure Default Initialization of Resource in Pivotal Spring Web Flow
5.9
MEDIUM
CVSS 3.1
EPSS 15.9%
描述
An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that process form submissions but do not have a sub-element to declare explicit data binding property mappings.
如何修補 CVE-2017-4971
要修補 CVE-2017-4971,請將受影響套件升級到下列已修補版本。
- —升級至 2.4.5 或更新版本
CVE-2017-4971 正在被利用嗎?
中等 — EPSS 為 15.9%,可持續追蹤但非最高優先。
受影響套件(1)
- >= 2.4.0, < 2.4.5
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.9 | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |