CVE-2024-22259
published 2024-03-16CVE-2024-22259: Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation…
PriorityP343high8.1CVSS 3.1
AVNACLPRNUIRSUCHIHAN
EPSS
2.57%
83.4th percentile
Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing validation checks.
This is the same as CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| atlassian | confluence_data_center | — | — |
| debian | libspring-java | — | — |
| vmware | spring_framework | < 5.3.33 | 5.3.33 |
| vmware | spring_framework | >= 6.0.0 < 6.0.18 | 6.0.18 |
| vmware | spring_framework | >= 6.1.0 < 6.1.5 | 6.1.5 |
Detection & IOCsextracted from sources · hover to see the quote
- →The vulnerability is exploitable remotely over HTTP; flag unexpected outbound HTTP requests originating from Spring Framework applications as potential SSRF exploitation ↗
- →Monitor for open redirect abuse via externally supplied URL query parameters passed to Spring's UriComponentsBuilder, particularly where host validation is performed before use ↗
- →Affected component is org.springframework:spring-web; detect presence of vulnerable spring-web dependency in Confluence Data Center and Server deployments ↗
- ·Red Hat Fuse 7 does not use the affected function by default, but the function remains available to users, requiring input validation ↗
- ·No mitigation meeting Red Hat's criteria (ease of use, deployment, applicability, stability) is currently available for CVE-2024-22262 (same vulnerability class) ↗
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
ghsa8.1HIGH
osv8.1HIGH
vendor_debian8.1LOW
vendor_oracle8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Spring Framework) — CVE-2024-22259
vendor_oracle·2024-07-15·CVSS 8.1
CVE-2024-22259 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Spring Framework) — CVE-2024-22259
Oracle Oracle Fusion Middleware Risk Matrix: Third Party (Spring Framework) vulnerability
CVE: CVE-2024-22259
CVSS: 8.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Red Hat
springframework: URL Parsing with Host Validation
vendor_redhat·2024-04-16·CVSS 8.1
CVE-2024-22262 [HIGH] CWE-601 springframework: URL Parsing with Host Validation
springframework: URL Parsing with Host Validation
Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing validation checks.
This is the same as CVE-2024-22259 https://spring.io/security/cve-2024-22259 and CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.
A flaw was found in the Spring Framework. Applications that use UriComponentsBuilder to parse an externally provided URL, for example, through a query parameter, and perform validation checks on the host of the parsed URL may be vulnerable to an
Oracle
Oracle Oracle Communications Risk Matrix: Configuration (Spring Web Services) — CVE-2024-22259
vendor_oracle·2024-04-15·CVSS 8.1
CVE-2024-22259 [HIGH] Oracle Oracle Communications Risk Matrix: Configuration (Spring Web Services) — CVE-2024-22259
Oracle Oracle Communications Risk Matrix: Configuration (Spring Web Services) vulnerability
CVE: CVE-2024-22259
CVSS: 8.1
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Red Hat
springframework: URL Parsing with Host Validation
vendor_redhat·2024-03-16·CVSS 8.1
CVE-2024-22259 [HIGH] CWE-601 springframework: URL Parsing with Host Validation
springframework: URL Parsing with Host Validation
Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing validation checks.
This is the same as CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.
A vulnerability was found in Spring Framework. Affected versions of this package are vulnerable to an Open Redirect when using UriComponentsBuilder to parse an externally provided URL and perform validation checks on the host of the parsed URL.
Package: springframework (A-MQ Clients 2)
Debian
CVE-2024-22262: libspring-java - Applications that use UriComponentsBuilder to parse an externally provided URL (...
vendor_debian·2024·CVSS 8.1
CVE-2024-22262 [HIGH] CVE-2024-22262: libspring-java - Applications that use UriComponentsBuilder to parse an externally provided URL (...
Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing validation checks. This is the same as CVE-2024-22259 https://spring.io/security/cve-2024-22259 and CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
Debian
CVE-2024-22259: libspring-java - Applications that use UriComponentsBuilder in Spring Framework to parse an exter...
vendor_debian·2024·CVSS 8.1
CVE-2024-22259 [HIGH] CVE-2024-22259: libspring-java - Applications that use UriComponentsBuilder in Spring Framework to parse an exter...
Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing validation checks. This is the same as CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
Atlassian
CVE-2024-22259: SSRF (Server-Side Request Forgery) org.springframework:spring-web Dependency in Confluence Data Center and Server
vendor_atlassian·CVSS 8.1
CVE-2024-22259 [HIGH] CVE-2024-22259: SSRF (Server-Side Request Forgery) org.springframework:spring-web Dependency in Confluence Data Center and Server
CVE-2024-22259: SSRF (Server-Side Request Forgery) org.springframework:spring-web Dependency in Confluence Data Center and Server
SSRF (Server-Side Request Forgery) org.springframework:spring-web Dependency in Confluence Data Center and Server
CVE: CVE-2024-22259
Affected products: Confluence Data Center
GHSA
Spring Framework URL Parsing with Host Validation
ghsa·2024-04-16·CVSS 8.1
CVE-2024-22262 [HIGH] CWE-601 Spring Framework URL Parsing with Host Validation
Spring Framework URL Parsing with Host Validation
Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing validation checks.
This is the same as CVE-2024-22259 https://spring.io/security/cve-2024-22259 and CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.
OSV
Spring Framework URL Parsing with Host Validation
osv·2024-04-16·CVSS 8.1
CVE-2024-22262 [HIGH] Spring Framework URL Parsing with Host Validation
Spring Framework URL Parsing with Host Validation
Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing validation checks.
This is the same as CVE-2024-22259 https://spring.io/security/cve-2024-22259 and CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.
OSV
CVE-2024-22262: Applications that use UriComponentsBuilder to parse an externally provided URL (e
osv·2024-04-16·CVSS 8.1
CVE-2024-22262 [HIGH] CVE-2024-22262: Applications that use UriComponentsBuilder to parse an externally provided URL (e
Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing validation checks. This is the same as CVE-2024-22259 https://spring.io/security/cve-2024-22259 and CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.
OSV
Spring Framework URL Parsing with Host Validation Vulnerability
osv·2024-03-16·CVSS 8.1
CVE-2024-22259 [HIGH] Spring Framework URL Parsing with Host Validation Vulnerability
Spring Framework URL Parsing with Host Validation Vulnerability
Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing validation checks.
This is the same as CVE-2024-22243 https://spring.io/security/cve-2024-22243, but with different input.
GHSA
Spring Framework URL Parsing with Host Validation Vulnerability
ghsa·2024-03-16·CVSS 8.1
CVE-2024-22259 [HIGH] CWE-601 Spring Framework URL Parsing with Host Validation Vulnerability
Spring Framework URL Parsing with Host Validation Vulnerability
Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing validation checks.
This is the same as CVE-2024-22243 https://spring.io/security/cve-2024-22243, but with different input.
OSV
CVE-2024-22259: Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e
osv·2024-03-16·CVSS 8.1
CVE-2024-22259 [HIGH] CVE-2024-22259: Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e
Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing validation checks. This is the same as CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.
No detection rules found.
No public exploits indexed.
2024-03-16
Published