CVE-2020-5421
published 2020-09-19CVE-2020-5421: In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks…
PriorityP341medium6.5CVSS 3.1
AVNACHPRLUIRSCCLIHAN
EPSS
10.74%
95.3th percentile
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
Affected
75 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | libspring-java | < libspring-java 4.3.30-1 (bookworm) | libspring-java 4.3.30-1 (bookworm) |
| oracle | commerce_guided_search | — | — |
| oracle | communications_brm | — | — |
| oracle | communications_brm | — | — |
| oracle | communications_design_studio | — | — |
| oracle | communications_design_studio | — | — |
| oracle | communications_design_studio | — | — |
| oracle | communications_session_report_manager | 8.2.1 – 8.2.2.1 | — |
| oracle | communications_unified_inventory_management | — | — |
| oracle | communications_unified_inventory_management | — | — |
| oracle | endeca_information_discovery_integrator | — | — |
| oracle | enterprise_data_quality | — | — |
| oracle | enterprise_data_quality | — | — |
| oracle | financial_services_analytical_applications_infrastructure | 8.0.6 – 8.1.0 | — |
| oracle | flexcube_private_banking | — | — |
| oracle | flexcube_private_banking | — | — |
| oracle | fusion_middleware | — | — |
| oracle | fusion_middleware | — | — |
| oracle | goldengate_application_adapters | — | — |
| oracle | healthcare_master_person_index | — | — |
| oracle | hyperion_infrastructure_technology | — | — |
| oracle | insurance_policy_administration | — | — |
| oracle | insurance_policy_administration | — | — |
| oracle | insurance_policy_administration | — | — |
| oracle | insurance_policy_administration | 11.1.0 – 11.3.0 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →RFD attack bypass vector: look for HTTP requests containing a jsessionid path parameter appended to URLs (e.g., ';jsessionid=...' in the URL path), which may be used to bypass Content-Disposition protections in Spring Framework ↗
- →Focus detection on Spring Framework versions 5.2.0–5.2.8, 5.1.0–5.1.17, 5.0.0–5.0.18, and 4.3.0–4.3.28 as the affected range for this RFD bypass ↗
- →The attack surface is the spring-web component specifically; systems not shipping spring-web are not affected and can be excluded from detection scope ↗
- ·Exploitability is browser-dependent; not all browsers will be susceptible to the RFD bypass via the jsessionid path parameter ↗
- ·Oracle rates this as non-remotely-exploitable (Remote exploit: No) in its risk matrices, which may affect prioritization in network-exposed deployments ↗
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N
nvdv3.08.7HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
nvdv2.03.6LOWAV:N/AC:H/Au:S/C:P/I:P/A:N
ghsa9.6CRITICAL
osv9.6CRITICAL
vendor_debian9.6LOW
vendor_redhat9.6CRITICAL
vendor_oracle8.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Improper Input Validation in Spring Framework
osv·2021-04-30·CVSS 9.6
CVE-2020-5421 [CRITICAL] Improper Input Validation in Spring Framework
Improper Input Validation in Spring Framework
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
GHSA
Improper Input Validation in Spring Framework
ghsa·2021-04-30·CVSS 9.6
CVE-2020-5421 [CRITICAL] CWE-35 Improper Input Validation in Spring Framework
Improper Input Validation in Spring Framework
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
OSV
CVE-2020-5421: In Spring Framework versions 5
osv·2020-09-19·CVSS 9.6
CVE-2020-5421 [CRITICAL] CVE-2020-5421: In Spring Framework versions 5
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Spring Framework) — CVE-2020-5421
vendor_oracle·2024-01-15·CVSS 6.5
CVE-2020-5421 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Spring Framework) — CVE-2020-5421
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Spring Framework) vulnerability
CVE: CVE-2020-5421
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Oracle
Oracle Oracle Systems Risk Matrix: Software (Spring Framework) — CVE-2020-5421
vendor_oracle·2022-04-15·CVSS 6.5
CVE-2020-5421 [MEDIUM] Oracle Oracle Systems Risk Matrix: Software (Spring Framework) — CVE-2020-5421
Oracle Oracle Systems Risk Matrix: Software (Spring Framework) vulnerability
CVE: CVE-2020-5421
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Inventory (Spring Framework) — CVE-2020-5421
vendor_oracle·2022-01-15·CVSS 6.5
CVE-2020-5421 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Inventory (Spring Framework) — CVE-2020-5421
Oracle Oracle Communications Applications Risk Matrix: Inventory (Spring Framework) vulnerability
CVE: CVE-2020-5421
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: General (Spring Framework) — CVE-2020-5421
vendor_oracle·2021-07-15·CVSS 8.8
CVE-2020-5421 [MEDIUM] Oracle Oracle Fusion Middleware Risk Matrix: General (Spring Framework) — CVE-2020-5421
Oracle Oracle Fusion Middleware Risk Matrix: General (Spring Framework) vulnerability
CVE: CVE-2020-5421
CVSS: 8.8
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Reservations (Spring Framework) — CVE-2020-5421
vendor_oracle·2021-04-15·CVSS 8.8
CVE-2020-5421 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Reservations (Spring Framework) — CVE-2020-5421
Oracle Oracle Communications Applications Risk Matrix: Reservations (Spring Framework) vulnerability
CVE: CVE-2020-5421
CVSS: 8.8
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2021 (APR 2021)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Orchestration, Processor and Messages (Spring Framework) — CVE-2020-5421
vendor_oracle·2021-01-15·CVSS 6.5
CVE-2020-5421 [MEDIUM] Oracle Oracle Communications Applications Risk Matrix: Orchestration, Processor and Messages (Spring Framework) — CVE-2020-5421
Oracle Oracle Communications Applications Risk Matrix: Orchestration, Processor and Messages (Spring Framework) vulnerability
CVE: CVE-2020-5421
CVSS: 6.5
Protocol: TCP/IP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
Red Hat
springframework: RFD protection bypass via jsessionid
vendor_redhat·2020-09-17·CVSS 9.6
CVE-2020-5421 [CRITICAL] springframework: RFD protection bypass via jsessionid
springframework: RFD protection bypass via jsessionid
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
In Spring Framework, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
Statement: This issue does not affect the version of SpringFramework (embedded in rhvm-dependencies) shipped with Red Hat Virtualization, as it does not provide support for spring-web.
In Red Hat Gluster Storage 3, SpringFramework (embedded in rhvm-dependencies) was shipped as a part of Red Hat Glus
Debian
CVE-2020-5421: libspring-java - In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3....
vendor_debian·2020·CVSS 9.6
CVE-2020-5421 [CRITICAL] CVE-2020-5421: libspring-java - In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3....
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
Scope: local
bookworm: resolved (fixed in 4.3.30-1)
bullseye: resolved (fixed in 4.3.30-1)
forky: resolved (fixed in 4.3.30-1)
sid: resolved (fixed in 4.3.30-1)
trixie: resolved (fixed in 4.3.30-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-5421 springframework: RFD protection bypass via jsessionid [fedora-all]
bugzilla·2020-09-21·CVSS 6.5
CVE-2020-5421 [MEDIUM] CVE-2020-5421 springframework: RFD protection bypass via jsessionid [fedora-all]
CVE-2020-5421 springframework: RFD protection bypass via jsessionid [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versi
Bugzilla
CVE-2020-5421 springframework: RFD protection bypass via jsessionid
bugzilla·2020-09-21·CVSS 9.6
CVE-2020-5421 [CRITICAL] CVE-2020-5421 springframework: RFD protection bypass via jsessionid
CVE-2020-5421 springframework: RFD protection bypass via jsessionid
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
Reference:
https://tanzu.vmware.com/security/cve-2020-5421
Discussion:
Created springframework tracking bugs for this issue:
Affects: fedora-all [bug 1881159]
---
Statement:
This issue does not affect the version of SpringFramework (embedded in rhvm-dependencies) shipped with Red Hat Virtualization, as it does not provide support for spring-web.
In Red Hat Gluster Storage 3, SpringFramework (embedded in rhvm-dependencies) was shipped as a part of
Tenable
Oracle October 2022 Critical Patch Update Addresses 179 CVEs
blogs_tenable·2022-10-19
Oracle October 2022 Critical Patch Update Addresses 179 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
https://lists.apache.org/thread.html/r1c679c43fa4f7846d748a937955c7921436d1b315445978254442163%40%3Ccommits.ambari.apache.org%3Ehttps://lists.apache.org/thread.html/r1eccdbd7986618a7319ee7a533bd9d9bf6e8678e59dd4cca9b5b2d7a%40%3Cissues.ambari.apache.org%3Ehttps://lists.apache.org/thread.html/r3589ed0d18edeb79028615080d5a0e8878856436bb91774a3196d9eb%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/r503e64b43a57fd68229cac4a869d1a9a2eac9e75f8719cad3a840211%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/r5c95eff679dfc642e9e4ab5ac6d202248a59cb1e9457cfbe8b729ac5%40%3Cissues.ambari.apache.org%3Ehttps://lists.apache.org/thread.html/r7e6a213eea7f04fc6d9e3bd6eb8d68c4df92a22e956e95cb2c482865%40%3Cissues.hive.apache.org%3Ehttps://lists.apache.org/thread.html/r8b496b1743d128e6861ee0ed3c3c48cc56c505b38f84fa5baf7ae33a%40%3Cdev.ambari.apache.org%3Ehttps://lists.apache.org/thread.html/r918caad55dcc640a16753b00d8d6acb90b4e36de4b6156d0867246ec%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/r9f13cccb214495e14648d2c9b8f2c6072fd5219e74502dd35ede81e1%40%3Cdev.ambari.apache.org%3Ehttps://lists.apache.org/thread.html/ra889d95141059c6cbe77dd80249bb488ae53b274b5f3abad09d9511d%40%3Cuser.ignite.apache.org%3Ehttps://lists.apache.org/thread.html/raf7ca57033e537e4f9d7df7f192fa6968c1e49409b2348e08d807ccb%40%3Cuser.ignite.apache.org%3Ehttps://lists.apache.org/thread.html/rb18ed999153ef0f0cb7af03efe0046c42c7242fd77fbd884a75ecfdc%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/rc9efaf6db98bee19db1bc911d0fa442287dac5cb229d4aaa08b6a13d%40%3Cissues.hive.apache.org%3Ehttps://lists.apache.org/thread.html/rd462a8b0dfab4c15e67c0672cd3c211ecd0e4f018f824082ed54f665%40%3Cissues.hive.apache.org%3Ehttps://lists.apache.org/thread.html/re014a49d77f038ba70e5e9934d400af6653e8c9ac110d32b1254127e%40%3Cdev.ranger.apache.org%3Ehttps://lists.apache.org/thread.html/rf00d8f4101a1c1ea4de6ea1e09ddf7472cfd306745c90d6da87ae074%40%3Cdev.hive.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20210513-0009/https://tanzu.vmware.com/security/cve-2020-5421https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttps://lists.apache.org/thread.html/r1c679c43fa4f7846d748a937955c7921436d1b315445978254442163%40%3Ccommits.ambari.apache.org%3Ehttps://lists.apache.org/thread.html/r1eccdbd7986618a7319ee7a533bd9d9bf6e8678e59dd4cca9b5b2d7a%40%3Cissues.ambari.apache.org%3Ehttps://lists.apache.org/thread.html/r3589ed0d18edeb79028615080d5a0e8878856436bb91774a3196d9eb%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/r503e64b43a57fd68229cac4a869d1a9a2eac9e75f8719cad3a840211%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/r5c95eff679dfc642e9e4ab5ac6d202248a59cb1e9457cfbe8b729ac5%40%3Cissues.ambari.apache.org%3Ehttps://lists.apache.org/thread.html/r7e6a213eea7f04fc6d9e3bd6eb8d68c4df92a22e956e95cb2c482865%40%3Cissues.hive.apache.org%3Ehttps://lists.apache.org/thread.html/r8b496b1743d128e6861ee0ed3c3c48cc56c505b38f84fa5baf7ae33a%40%3Cdev.ambari.apache.org%3Ehttps://lists.apache.org/thread.html/r918caad55dcc640a16753b00d8d6acb90b4e36de4b6156d0867246ec%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/r9f13cccb214495e14648d2c9b8f2c6072fd5219e74502dd35ede81e1%40%3Cdev.ambari.apache.org%3Ehttps://lists.apache.org/thread.html/ra889d95141059c6cbe77dd80249bb488ae53b274b5f3abad09d9511d%40%3Cuser.ignite.apache.org%3Ehttps://lists.apache.org/thread.html/raf7ca57033e537e4f9d7df7f192fa6968c1e49409b2348e08d807ccb%40%3Cuser.ignite.apache.org%3Ehttps://lists.apache.org/thread.html/rb18ed999153ef0f0cb7af03efe0046c42c7242fd77fbd884a75ecfdc%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/rc9efaf6db98bee19db1bc911d0fa442287dac5cb229d4aaa08b6a13d%40%3Cissues.hive.apache.org%3Ehttps://lists.apache.org/thread.html/rd462a8b0dfab4c15e67c0672cd3c211ecd0e4f018f824082ed54f665%40%3Cissues.hive.apache.org%3Ehttps://lists.apache.org/thread.html/re014a49d77f038ba70e5e9934d400af6653e8c9ac110d32b1254127e%40%3Cdev.ranger.apache.org%3Ehttps://lists.apache.org/thread.html/rf00d8f4101a1c1ea4de6ea1e09ddf7472cfd306745c90d6da87ae074%40%3Cdev.hive.apache.org%3Ehttps://security.netapp.com/advisory/ntap-20210513-0009/https://tanzu.vmware.com/security/cve-2020-5421https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2021.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2020-09-19
Published