VDB

DEBIAN-CVE-2018-11039

DEBIAN-CVE-2018-11039 PUBLISHED CVSS 5.900000095367432 MEDIUM

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.

Risk Scores

CVSS v3.1
5.900000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
Debian:12libspring-java0, 0, 0
Debian:14libspring-java0, 0, 0
Debian:11libspring-java0, 0, 0
Debian:13libspring-java0, 0, 0

Timeline

  • Jun 25, 2018 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›