Spring Framework
cpe:2.3:a:springsource:spring_framework:*:*:*:*:*:*:*
- >= 7.0.0, <= 7.0.7
- >= 6.2.0, <= 6.2.18
- >= 6.1.0, <= 6.1.27
- >= 5.3.0, <= 5.3.48
A vulnerability exists in Spring MVC and Spring WebFlux applications that configure a mapping for '/**' without an explicitly specified view name. This flaw allows an attacker to create a link that triggers a 302 redirect to an arbitrary external host using the 'redirect:' prefix. Additionally, in Spring MVC applications with the same conditions, internal redirects can be crafted using the 'forward:' prefix.
Exploitation of this vulnerability allows for open redirect attacks, where users can be redirected to malicious external sites, potentially leading to phishing or other malicious activities. In the case of Spring MVC, internal redirects can also be exploited, which could be used to bypass certain application logic or security controls.
Users should upgrade to Spring Framework versions 7.0.8, 6.2.19, 6.1.28, or 5.3.49. Instructions for upgrading to these versions are available on the Spring Enterprise website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.