Lucene search

K
f5F5F5:K000139218
HistoryApr 09, 2024 - 12:00 a.m.

K000139218 : CVE-2024-22243 Spring Framework vulnerability

2024-04-0900:00:00
my.f5.com
34
spring framework
uri validation
open redirect
ssrf attack

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

26.6%

Security Advisory Description

Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect <https://cwe.mitre.org/data/definitions/601.html&gt; attack or to a SSRF attack if the URL is used after passing validation checks. (CVE-2024-22243)

Impact

There is no impact; F5 products are not affected by this vulnerability.