CVE-2017-4971
moderate-risk
Published 2017-06-13
An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that process form submissions but do not have a sub-element to declare explicit data binding property mappings.
Do I need to act?
!
75.4% chance of exploitation in next 30 days
EPSS score — higher than 25% of all CVEs
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
5
CVSS 5.9/10
Medium
NETWORK
/ HIGH complexity
Affected Products (4)
Affected Vendors
References (6)
Third Party Advisory
http://www.securityfocus.com/bid/98785
Issue Tracking
https://jira.spring.io/browse/SWF-1700
Mitigation
https://pivotal.io/security/cve-2017-4971
Third Party Advisory
http://www.securityfocus.com/bid/98785
Issue Tracking
https://jira.spring.io/browse/SWF-1700
Mitigation
https://pivotal.io/security/cve-2017-4971
48
/ 100
moderate-risk
Severity
18/34 · Moderate
Exploitability
20/34 · Moderate
Exposure
10/34 · Low