Lucene search

K
cve[email protected]CVE-2018-1199
HistoryMar 16, 2018 - 8:29 p.m.

CVE-2018-1199

2018-03-1620:29:00
CWE-20
web.nvd.nist.gov
97
cve-2018-1199
spring security
spring framework
url path parameters
security constraint bypass
web security
path parameters
servlet containers
encoding vulnerabilities

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

5.3

Confidence

High

EPSS

0.002

Percentile

55.1%

Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.3.x before 4.3.14 and 5.0.x before 5.0.3) does not consider URL path parameters when processing security constraints. By adding a URL path parameter with special encodings, an attacker may be able to bypass a security constraint. The root cause of this issue is a lack of clarity regarding the handling of path parameters in the Servlet Specification. Some Servlet containers include path parameters in the value returned for getPathInfo() and some do not. Spring Security uses the value returned by getPathInfo() as part of the process of mapping requests to security constraints. In this particular attack, different character encodings used in path parameters allows secured Spring MVC static resource URLs to be bypassed.

Affected configurations

Vulners
NVD
Node
dell_emcspring_by_pivotalRange4.2.04.2.3
OR
dell_emcspring_by_pivotalMatch5.0.0
OR
dell_emcspring_by_pivotalRange4.3.04.3.13

CNA Affected

[
  {
    "product": "Spring by Pivotal",
    "vendor": "Dell EMC",
    "versions": [
      {
        "status": "affected",
        "version": "spring Security 4.1.0 - 4.1.4, 4.2.0 - 4.2.3, 5.0.0"
      },
      {
        "status": "affected",
        "version": "Spring Framework 5.0.0 - 5.0.2, 4.3.0 - 4.3.13"
      },
      {
        "status": "affected",
        "version": "Older unmaintained versions of Spring Security & Spring Framework were not analyzed and may be impacted"
      }
    ]
  }
]

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

5.3

Confidence

High

EPSS

0.002

Percentile

55.1%