Skip to main content

CVE-2018-1272

Severity

5.3

Description

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote client, and then uses that input to make a multipart request to another server (server B), it can be exposed to an attack, where an extra multipart is inserted in the content of the request from server A, causing server B to use the wrong value for a part it expects. This could to lead privilege escalation, for example, if the part content represents a username or user roles.

Mitigation

We recommend upgrading to a version of this component that is not vulnerable to this specific issue.

Project

Apache ActiveMQ

Category
CAPEC-233 – Privilege Escalation
Tags
data
Date Disclosed

2018-04-06

Date Discovered

2017-12-06

Apache ActiveMQ 5.15.x

First release:
2017-06-27
CVEs:
25
Support Lifecycle:
Namespace:
javax
Feel Vulnerable? 

Contact us so we can help you.

* These fields are required.