CVE-2017-8039
Insecure Default Initialization of Resource in Pivotal Spring Web Flow
5.9
MEDIUM
CVSS 3.1
EPSS 0.96%
描述
An issue was discovered in Pivotal Spring Web Flow through 2.4.5. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that process form submissions but do not have a sub-element to declare explicit data binding property mappings. NOTE: this issue exists because of an incomplete fix for CVE-2017-4971.
如何修補 CVE-2017-8039
要修補 CVE-2017-8039,請將受影響套件升級到下列已修補版本。
- —升級至 2.4.6 或更新版本
CVE-2017-8039 正在被利用嗎?
低 — EPSS 為 1.0%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- from 0, < 2.4.6
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.9 | CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N |