Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:6806
HistoryJun 18, 2018 - 5:37 a.m.

Cross-Site Tracing (XST)

2018-06-1805:37:04
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
34

0.003 Low

EPSS

Percentile

66.3%

spring-web is vulnerable to cross-site tracing (XST) attacks. The vulnerability exists as HiddenHttpMethodFilter allows web applications to change existing HTTP request method to any HTTP method, causing applications with existing cross-site scripting (XSS) vulnerability to be vulnerable to XST.