PT-2026-82401 · Vmware · Spring Framework
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Spring Framework versions 7.0.0 through 7.0.8
Spring Framework versions 6.2.0 through 6.2.19
Description
UrlHandlerFilter in both Spring MVC and Spring WebFlux is susceptible to an open redirect when configured with very broadly matching patterns. An open redirect occurs when an application takes a user-provided input and uses it to redirect the user to an external site without sufficient validation.
Recommendations
Update Spring Framework versions 7.0.0 through 7.0.8 to a newer version.
Update Spring Framework versions 6.2.0 through 6.2.19 to a newer version.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spring Framework