PT-2024-1921 · Unknown+2 · Spring Framework+3

·

CVE-2024-22243

·

Published

2024-02-21

·

Updated

2026-09-01

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Spring Framework versions prior to the fixed version
Description The issue arises from insufficient validation of user-input data in the Spring Framework, potentially allowing an attacker to perform a Server-Side Request Forgery (SSRF) attack or an open redirect attack. This can occur when applications use UriComponentsBuilder to parse externally provided URLs and then perform validation checks on the host of the parsed URL. If the URL is used after passing these validation checks, it may be vulnerable to such attacks. The vulnerability can be exploited by including a left square bracket symbol in the user info segment of a URL, which can lead to the UriComponentsBuilder returning a host name that differs from the interpretation of major browsers, thus potentially bypassing whitelist restrictions and accessing closed resources.
Recommendations To resolve the issue, upgrade to the latest version of the Spring Framework. If upgrading is not possible, apply the recommended fixed versions for your specific version of the framework. As a temporary workaround, consider disabling the use of UriComponentsBuilder for parsing externally provided URLs until a patch is available. Restrict access to sensitive resources and validate all user-input data to minimize the risk of exploitation.

Exploit

Fix

SSRF

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-01709
CVE-2024-22243
ECHO-6AEF-BC09-6CFF
GHSA-CCGV-VJ62-XF9H

Affected Products

Bamboo
Confluence
Debian
Spring Framework