PT-2012-1567 · Vmware Springsource · Spring Framework

Moritz Muehlenhoff

·

Publicado

2012-12-05

·

Atualizado

2022-05-17

·

CVE-2011-2730

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions VMware SpringSource Spring Framework versions prior to 2.5.6.SEC03 VMware SpringSource Spring Framework versions prior to 2.5.7.SR023 VMware SpringSource Spring Framework versions prior to 3.0.6
Description The issue allows remote attackers to obtain sensitive information via specific attributes in various tags when a container supports Expression Language (EL). This is due to the evaluation of EL expressions in tags twice. The affected attributes include name in spring:hasBindErrors tags, path in spring:bind or spring:nestedpath tags, and several attributes in spring:message, spring:theme, and spring:transform tags, such as arguments, code, text, var, scope, message, and value.
Recommendations For versions prior to 2.5.6.SEC03, update to version 2.5.6.SEC03 or later. For versions prior to 2.5.7.SR023, update to version 2.5.7.SR023 or later. For versions prior to 3.0.6, update to version 3.0.6 or later. As a temporary workaround, consider restricting the use of Expression Language (EL) in tags until a patch is applied. Avoid using the vulnerable attributes in the affected tags to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-2730
DSA-2504-1
GHSA-WV88-PF73-X22P
RHSA-2013:0191
RHSA-2013:0192
RHSA-2013:0193
RHSA-2013:0195
RHSA-2013:0196
RHSA-2013:0197

Produtos afetados

Spring Framework