CVE-2018-1199
published 2018-03-16CVE-2018-1199: Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.3.x before 4.3.14 and 5.0.x before…
PriorityP430medium5.3CVSS 3.1
AVNACLPRNUINSUCLINAN
EPSS
2.86%
85.2th percentile
Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.3.x before 4.3.14 and 5.0.x before 5.0.3) does not consider URL path parameters when processing security constraints. By adding a URL path parameter with special encodings, an attacker may be able to bypass a security constraint. The root cause of this issue is a lack of clarity regarding the handling of path parameters in the Servlet Specification. Some Servlet containers include path parameters in the value returned for getPathInfo() and some do not. Spring Security uses the value returned by getPathInfo() as part of the process of mapping requests to security constraints. In this particular attack, different character encodings used in path parameters allows secured Spring MVC static resource URLs to be bypassed.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libspring-java | < libspring-java 4.3.14-1 (bookworm) | libspring-java 4.3.14-1 (bookworm) |
| dell_emc | spring_by_pivotal | — | — |
| dell_emc | spring_by_pivotal | — | — |
| dell_emc | spring_by_pivotal | — | — |
| oracle | rapid_planning | — | — |
| oracle | rapid_planning | — | — |
| oracle | retail_xstore_point_of_service | — | — |
| redhat | fuse | — | — |
| vmware | spring_framework | >= 4.3.0 < 4.3.14 | 4.3.14 |
| vmware | spring_framework | >= 5.0.0 < 5.0.3 | 5.0.3 |
| vmware | spring_security | >= 4.1.0 < 4.1.5 | 4.1.5 |
| vmware | spring_security | >= 4.2.0 < 4.2.4 | 4.2.4 |
| vmware | spring_security | >= 5.0.0 < 5.0.1 | 5.0.1 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.3MEDIUM
vendor_debian5.3MEDIUM
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Input Validation in org.springframework.security:spring-security-core, org.springframework.security:spring-security-core , and org.springframework:spring-core
osv·2018-10-17
CVE-2018-1199 [MEDIUM] Improper Input Validation in org.springframework.security:spring-security-core, org.springframework.security:spring-security-core , and org.springframework:spring-core
Improper Input Validation in org.springframework.security:spring-security-core, org.springframework.security:spring-security-core , and org.springframework:spring-core
Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.3.x before 4.3.14 and 5.0.x before 5.0.3) does not consider URL path parameters when processing security constraints. By adding a URL path parameter with special encodings, an attacker may be able to bypass a security constraint. The root cause of this issue is a lack of clarity regarding the handling of path parameters in the Servlet Specification. Some Servlet containers include path parameters in the value returned for getPathInfo() and some do not. Spring Security uses the value returned by getPathInfo
GHSA
Improper Input Validation in org.springframework.security:spring-security-core, org.springframework.security:spring-security-core , and org.springframework:spring-core
ghsa·2018-10-17
CVE-2018-1199 [MEDIUM] CWE-20 Improper Input Validation in org.springframework.security:spring-security-core, org.springframework.security:spring-security-core , and org.springframework:spring-core
Improper Input Validation in org.springframework.security:spring-security-core, org.springframework.security:spring-security-core , and org.springframework:spring-core
Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.3.x before 4.3.14 and 5.0.x before 5.0.3) does not consider URL path parameters when processing security constraints. By adding a URL path parameter with special encodings, an attacker may be able to bypass a security constraint. The root cause of this issue is a lack of clarity regarding the handling of path parameters in the Servlet Specification. Some Servlet containers include path parameters in the value returned for getPathInfo() and some do not. Spring Security uses the value returned by getPathInfo
OSV
CVE-2018-1199: Spring Security (Spring Security 4
osv·2018-03-16·CVSS 5.3
CVE-2018-1199 [MEDIUM] CVE-2018-1199: Spring Security (Spring Security 4
Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.3.x before 4.3.14 and 5.0.x before 5.0.3) does not consider URL path parameters when processing security constraints. By adding a URL path parameter with special encodings, an attacker may be able to bypass a security constraint. The root cause of this issue is a lack of clarity regarding the handling of path parameters in the Servlet Specification. Some Servlet containers include path parameters in the value returned for getPathInfo() and some do not. Spring Security uses the value returned by getPathInfo() as part of the process of mapping requests to security constraints. In this particular attack, different character encodings used in path parameters allows secured Sp
Red Hat
spring-framework: Improper URL path validation allows for bypassing of security checks on static resources
vendor_redhat·2018-01-29·CVSS 5.3
CVE-2018-1199 [MEDIUM] CWE-20 spring-framework: Improper URL path validation allows for bypassing of security checks on static resources
spring-framework: Improper URL path validation allows for bypassing of security checks on static resources
Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.3.x before 4.3.14 and 5.0.x before 5.0.3) does not consider URL path parameters when processing security constraints. By adding a URL path parameter with special encodings, an attacker may be able to bypass a security constraint. The root cause of this issue is a lack of clarity regarding the handling of path parameters in the Servlet Specification. Some Servlet containers include path parameters in the value returned for getPathInfo() and some do not. Spring Security uses the value returned by getPathInfo() as part of the process of mapping requests to security con
Debian
CVE-2018-1199: libspring-java - Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0...
vendor_debian·2018·CVSS 5.3
CVE-2018-1199 [MEDIUM] CVE-2018-1199: libspring-java - Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0...
Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.3.x before 4.3.14 and 5.0.x before 5.0.3) does not consider URL path parameters when processing security constraints. By adding a URL path parameter with special encodings, an attacker may be able to bypass a security constraint. The root cause of this issue is a lack of clarity regarding the handling of path parameters in the Servlet Specification. Some Servlet containers include path parameters in the value returned for getPathInfo() and some do not. Spring Security uses the value returned by getPathInfo() as part of the process of mapping requests to security constraints. In this particular attack, different character encodings used in path parameters allows secured Sp
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-16643 ImageMagick: missing check for fputc function in multiple files
bugzilla·2018-09-07·CVSS 6.5
CVE-2018-16643 [MEDIUM] CVE-2018-16643 ImageMagick: missing check for fputc function in multiple files
CVE-2018-16643 ImageMagick: missing check for fputc function in multiple files
The functions ReadDCMImage in coders/dcm.c, ReadPWPImage in coders/pwp.c, ReadCALSImage in coders/cals.c, and ReadPICTImage in coders/pict.c in ImageMagick 7.0.8-4 do not check the return value of the fputc function, which allows remote attackers to cause a denial of service via a crafted image file.
References:
https://github.com/ImageMagick/ImageMagick/issues/1199
Upstream Patch:
https://github.com/ImageMagick/ImageMagick/commit/6b6bff054d569a77973f2140c0e86366e6168a6c
https://github.com/ImageMagick/ImageMagick6/commit/11d9dac3d991c62289d1ef7a097670166480e76c
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1626600]
---
Statement:
This issue affects the versions
Bugzilla
CVE-2018-1271 spring-framework: Directory traversal vulnerability with static resources on Windows filesystems
bugzilla·2018-04-24·CVSS 5.3
CVE-2018-1271 [MEDIUM] CVE-2018-1271 spring-framework: Directory traversal vulnerability with static resources on Windows filesystems
CVE-2018-1271 spring-framework: Directory traversal vulnerability with static resources on Windows filesystems
Spring Framework versions 5.0 to 5.0.4, 4.3 to 4.3.14, and older unsupported versions allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a request using a specially crafted URL that can lead a directory traversal attack.
This vulnerability does not affect applications that use versions of Spring Security patched for CVE-2018-1199.
External Reference:
https://pivotal.io/security/cve-2018-1271
Discussion:
This issue has been addressed in the following products:
Red Hat Openshift Application Ru
Bugzilla
Spring Security: Security bypass with static resources
bugzilla·2018-02-05·CVSS 5.3
[MEDIUM] Spring Security: Security bypass with static resources
Spring Security: Security bypass with static resources
Spring Security does not consider URL path parameters when processing security constraints. By adding a URL path parameter with special encodings, an attacker may be able to bypass a security constraint. The root cause of this issue is a lack of clarity regarding the handling of path parameters in the Servlet Specification (see below). Some Servlet containers include path parameters in the value returned for getPathInfo() and some do not. Spring Security uses the value returned by getPathInfo() as part of the process of mapping requests to security constraints. In this particular attack, different character encodings used in path parameters allows secured Spring MVC static resource URLs to be bypassed.
External References:
https://p
Bugzilla
CVE-2018-1199 springframework: spring-framework: Improper URL path validation allows for bypassing of security checks on static resources [fedora-all]
bugzilla·2018-01-30·CVSS 5.3
CVE-2018-1199 [MEDIUM] CVE-2018-1199 springframework: spring-framework: Improper URL path validation allows for bypassing of security checks on static resources [fedora-all]
CVE-2018-1199 springframework: spring-framework: Improper URL path validation allows for bypassing of security checks on static resources [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fed
Bugzilla
CVE-2018-1199 springframework-security: spring-framework: Improper URL path validation allows for bypassing of security checks on static resources [fedora-all]
bugzilla·2018-01-30·CVSS 5.3
CVE-2018-1199 [MEDIUM] CVE-2018-1199 springframework-security: spring-framework: Improper URL path validation allows for bypassing of security checks on static resources [fedora-all]
CVE-2018-1199 springframework-security: spring-framework: Improper URL path validation allows for bypassing of security checks on static resources [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog an
Bugzilla
CVE-2018-1199 spring-framework: Improper URL path validation allows for bypassing of security checks on static resources
bugzilla·2018-01-30·CVSS 5.3
CVE-2018-1199 [MEDIUM] CVE-2018-1199 spring-framework: Improper URL path validation allows for bypassing of security checks on static resources
CVE-2018-1199 spring-framework: Improper URL path validation allows for bypassing of security checks on static resources
Spring Framework and Spring Security do not consider URL path parameters when processing security constraints. By adding a URL path parameter with special encodings, an attacker may be able to bypass a security constraint and access Spring MVC static resource URLs.
Affected versions include:
* Spring Security 4.1.0 - 4.1.4, 4.2.0 - 4.2.3 and 5.0
* Spring Framework 4.3.0 - 4.3.14, and 5.0.0 - 5.0.2
Older unmaintained versions of Spring Security and Spring Framework may also be affected.
External References:
https://pivotal.io/security/cve-2018-1199
Mitigation:
As a general precaution, users are encouraged to separate public and private resources. For example, sepa
https://access.redhat.com/errata/RHSA-2018:2405https://lists.apache.org/thread.html/4ed49b103f64a0cecb38064f26cbf1389afc12124653da2d35166dbe%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/ab825fcade0b49becfa30235b3d54f4a51bb74ea96b6c9adb5d1378c%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/dcf8599b80e43a6b60482607adb76c64672772dc2d9209ae2170f369%40%3Cissues.activemq.apache.org%3Ehttps://pivotal.io/security/cve-2018-1199https://www.oracle.com/security-alerts/cpujul2020.htmlhttps://access.redhat.com/errata/RHSA-2018:2405https://lists.apache.org/thread.html/4ed49b103f64a0cecb38064f26cbf1389afc12124653da2d35166dbe%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/ab825fcade0b49becfa30235b3d54f4a51bb74ea96b6c9adb5d1378c%40%3Cissues.activemq.apache.org%3Ehttps://lists.apache.org/thread.html/dcf8599b80e43a6b60482607adb76c64672772dc2d9209ae2170f369%40%3Cissues.activemq.apache.org%3Ehttps://pivotal.io/security/cve-2018-1199https://www.oracle.com/security-alerts/cpujul2020.html
2018-03-16
Published