{"id":"GHSA-9gcm-f4x3-8jpw","summary":"Spring Framework Cross Site Tracing (XST)","details":"Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.","aliases":["CVE-2018-11039"],"modified":"2024-12-02T05:43:15.118408Z","published":"2018-10-16T17:35:54Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-06-16T21:28:30Z","nvd_published_at":"2018-06-25T15:29:00Z","cwe_ids":[],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-11039"},{"type":"WEB","url":"https://github.com/spring-projects/spring-framework/issues/21376"},{"type":"WEB","url":"https://github.com/spring-projects/spring-framework/commit/323ccf99e575343f63d56e229c25c35c170b7ec1"},{"type":"WEB","url":"https://github.com/spring-projects/spring-framework/commit/a5cd01a4c857aaaba7ccc51545fc73dd25b5cba5"},{"type":"WEB","url":"https://github.com/spring-projects/spring-framework/commit/dac97f1b7dac3e70ff603fb6fc9f205b95dd6b01"},{"type":"WEB","url":"https://github.com/spring-projects/spring-framework/commit/f2694a8ed93f1f63f87ce45d0bb638478b426acd"},{"type":"WEB","url":"https://github.com/spring-projects/spring-framework/commit/f64fa3dea10af125d612d3a997aece93d21bc875"},{"type":"WEB","url":"https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html"},{"type":"WEB","url":"https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html"},{"type":"WEB","url":"https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuoct2021.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujul2020.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujan2020.html"},{"type":"WEB","url":"https://spring.io/security/cve-2018-11039"},{"type":"WEB","url":"https://pivotal.io/security/cve-2018-11039"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2021/04/msg00022.html"},{"type":"PACKAGE","url":"https://github.com/spring-projects/spring-framework"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-9gcm-f4x3-8jpw"},{"type":"WEB","url":"http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html"},{"type":"WEB","url":"http://www.securityfocus.com/bid/107984"}],"affected":[{"package":{"name":"org.springframework:spring-web","ecosystem":"Maven","purl":"pkg:maven/org.springframework/spring-web"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"5.0.0"},{"fixed":"5.0.7"}]}],"versions":["5.0.0.RELEASE","5.0.1.RELEASE","5.0.2.RELEASE","5.0.3.RELEASE","5.0.4.RELEASE","5.0.5.RELEASE","5.0.6.RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-9gcm-f4x3-8jpw/GHSA-9gcm-f4x3-8jpw.json"}},{"package":{"name":"org.springframework:spring-web","ecosystem":"Maven","purl":"pkg:maven/org.springframework/spring-web"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.3.0"},{"fixed":"4.3.18"}]}],"versions":["4.3.0.RELEASE","4.3.1.RELEASE","4.3.10.RELEASE","4.3.11.RELEASE","4.3.12.RELEASE","4.3.13.RELEASE","4.3.14.RELEASE","4.3.15.RELEASE","4.3.16.RELEASE","4.3.17.RELEASE","4.3.2.RELEASE","4.3.3.RELEASE","4.3.4.RELEASE","4.3.5.RELEASE","4.3.6.RELEASE","4.3.7.RELEASE","4.3.8.RELEASE","4.3.9.RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/10/GHSA-9gcm-f4x3-8jpw/GHSA-9gcm-f4x3-8jpw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}