Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:6056
HistoryApr 06, 2018 - 2:06 a.m.

Privilege Escalation Through Multipart Content Pollution

2018-04-0602:06:57
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16

EPSS

0.002

Percentile

56.4%

spring-core is vulnerable to multipart content pollution. The application uses an insecure number generator to generate the multipart boundary parameter value, allowing a malicious user to make a informed guess the multipart boundary parameter value. A malicious user can potentially perform a privilege escalation attack by sending tampered requests to a server that the user does not have sufficient access control to.