PT-2017-12749 · Spring · Spring Batch Admin
Published
2017-08-18
·
Updated
2022-05-17
·
CVE-2017-12881
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Spring Batch Admin versions prior to 1.3.0
Description
A cross-site request forgery (CSRF) issue allows remote attackers to hijack the authentication of victims and submit arbitrary requests. This can be used to exploit other vulnerabilities, such as a file upload vulnerability.
Recommendations
For versions prior to 1.3.0, update to version 1.3.0 or later to resolve the issue. As a temporary workaround, consider implementing CSRF protection measures, such as token-based validation, to prevent unauthorized requests. Restrict access to sensitive functionality, like file uploads, to minimize the risk of exploitation.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spring Batch Admin