THREAT OPS › Threat News › [NVD] CVE-2018-11039 (MEDIUM 5.9) — Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a p
[NVD] CVE-2018-11039 (MEDIUM 5.9) — Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a p
CVE-2018-11039 CVSS: 5.9 MEDIUM Published: 2018-06-25T15:29:00.317
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or
Indicators of compromise
- CVE-2018-11039cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2018-11039