PT-2018-11102 · Pivotal · Spring Batch Admin

Wen Bin Kong

·

Published

2018-03-21

·

Updated

2019-10-09

·

CVE-2018-1230

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Pivotal Spring Batch Admin, all versions
Description The issue concerns the lack of cross-site request forgery protection. A remote unauthenticated user could craft a malicious site that executes requests to Spring Batch Admin. This has not been patched because Spring Batch Admin has reached end of life.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1230

Affected Products

Spring Batch Admin