Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2011-2732

CWE-94Code Injection7 documents7 sources
Severity
4.3MEDIUM
EPSS
7.2%
top 8.44%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedDec 5
Latest updateMay 17

Description

CRLF injection vulnerability in the logout functionality in VMware SpringSource Spring Security before 2.0.7 and 3.0.x before 3.0.6 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the spring-security-redirect parameter.

CVSS vector

AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages2 packages

🔴Vulnerability Details

3
GHSA
Improper Control of Generation of Code in Spring Security2022-05-17
OSV
Improper Control of Generation of Code in Spring Security2022-05-17
CVEList
CVE-2011-2732: CRLF injection vulnerability in the logout functionality in VMware SpringSource Spring Security before 22012-12-05

💥Exploits & PoCs

1
Exploit-DB
Spring Security - HTTP Header Injection2011-09-09

📋Vendor Advisories

1
Red Hat
Security: Header injection flaw due improper use of 'spring-security-redirect' parameter2011-09-09

💬Community

1
Bugzilla
CVE-2011-2732 Spring Security: Header injection flaw due improper use of 'spring-security-redirect' parameter2011-09-12
CVE-2011-2732 (MEDIUM CVSS 4.3) | CRLF injection vulnerability in the | cvebase.io