PT-2026-47665 · Spring+2 · Spring Framework+1
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Spring Framework versions 7.0.0 through 7.0.7
Spring Framework versions 6.2.0 through 6.2.18
Description
Incorrect host parsing in the
UriComponentsBuilder component may allow applications that use it to parse and validate externally provided URL strings to be exposed to a server-side request forgery (SSRF) attack. SSRF is a flaw that allows an attacker to induce the server-side application to make requests to an unintended location.Recommendations
Update Spring Framework versions 7.0.0 through 7.0.7 to a newer version.
Update Spring Framework versions 6.2.0 through 6.2.18 to a newer version.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spring Framework
Libspring-Java