CVE-2020-5397

Severity
5.3MEDIUM
EPSS
0.9%
top 25.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 17
Latest updateFeb 7

Description

Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail authentication. However a notable exception to this are Chrome based browsers when using client certificates for authentication since Chrome sends TL

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:NExploitability: 3.9 | Impact: 1.4

Affected Packages30 packages

Mavenorg.springframework:spring-webflux5.2.05.2.3
Mavenorg.springframework:spring-webmvc5.2.05.2.3
CVEListV5spring/spring_framework5.2v5.2.3.RELEASE
NVDvmware/spring_framework5.2.05.2.3
NVDoracle/mysql_enterprise_monitor4.0.04.0.12+1

Patches

🔴Vulnerability Details

4
OSV
CSRF attack via CORS preflight requests with Spring MVC or Spring WebFlux2020-01-21
GHSA
CSRF attack via CORS preflight requests with Spring MVC or Spring WebFlux2020-01-21
CVEList
CSRF Attack via CORS Preflight Requests with Spring MVC or Spring WebFlux2020-01-17
OSV
CVE-2020-5397: Spring Framework, versions 52020-01-17

📋Vendor Advisories

2
Red Hat
springframework: CSRF attack via CORS Preflight Requests with Spring MVC or Spring WebFlux2020-01-17
Debian
CVE-2020-5397: libspring-java - Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks t...2020

💬Community

2
Bugzilla
CVE-2020-5397 springframework: CSRF attack via CORS Preflight Requests with Spring MVC or Spring WebFlux [fedora-all]2020-02-07
Bugzilla
CVE-2020-5397 springframework: CSRF attack via CORS Preflight Requests with Spring MVC or Spring WebFlux2020-02-07