cbcvebase.
CVE-2020-5397
published 2020-01-17

CVE-2020-5397: Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or…

medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail authentication. However a notable exception to this are Chrome based browsers when using client certificates for authentication since Chrome sends TLS client certificates in CORS preflight requests in violation of spec requirements. No HTTP body can be sent or received as a result of this attack.

Affected

54 ranges· showing 25
VendorProductVersion rangeFixed in
debianlibspring-java
oracleapplication_testing_suite
oraclecommunications_brm_elastic_charging_engine
oraclecommunications_brm_elastic_charging_engine
oraclecommunications_diameter_signaling_router8.0.0 – 8.2.2
oraclecommunications_element_manager
oraclecommunications_element_manager
oraclecommunications_element_manager
oraclecommunications_policy_management
oraclecommunications_session_route_manager
oraclecommunications_session_route_manager
oraclecommunications_session_route_manager
oracleenterprise_manager_base_platform
oraclefinancial_services_regulatory_reporting_with_agilereporter
oracleflexcube_private_banking
oracleflexcube_private_banking
oraclehealthcare_master_person_index
oracleinsurance_calculation_engine11.0.0 – 11.3.1
oracleinsurance_policy_administration_j2ee
oracleinsurance_policy_administration_j2ee
oracleinsurance_policy_administration_j2ee
oracleinsurance_policy_administration_j2ee
oracleinsurance_policy_administration_j2ee
oracleinsurance_rules_palette
oracleinsurance_rules_palette

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM