{"id":"GHSA-45vg-2v73-vm62","summary":"Moderate severity vulnerability that affects org.springframework:spring-core","details":"The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.","aliases":["CVE-2015-0201"],"modified":"2024-12-02T05:51:24.734486Z","published":"2018-10-17T20:28:20Z","database_specific":{"github_reviewed_at":"2020-06-16T20:57:30Z","nvd_published_at":"2015-03-10T14:59:00Z","cwe_ids":[],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2015-0201"},{"type":"WEB","url":"https://github.com/spring-projects/spring-framework/commit/d63cfc8eebc396be009e733a81ebb4c984811f6e"},{"type":"WEB","url":"https://github.com/spring-projects/spring-framework/commit/dc5b5ca8ee09c890352f89b2dae58bc0132d6545"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-45vg-2v73-vm62"},{"type":"PACKAGE","url":"https://github.com/spring-projects/spring-framework"},{"type":"WEB","url":"https://pivotal.io/security/cve-2015-0201"}],"affected":[{"package":{"name":"org.springframework:spring-core","ecosystem":"Maven","purl":"pkg:maven/org.springframework/spring-core"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.1.0"},{"fixed":"4.1.5"}]}],"versions":["4.1.0.RELEASE","4.1.1.RELEASE","4.1.2.RELEASE","4.1.3.RELEASE","4.1.4.RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-45vg-2v73-vm62/GHSA-45vg-2v73-vm62.json"}}],"schema_version":"1.9.0"}