imPC@ndo EN

Tracker / CVE-2018-15756

CVE-2018-15756

Alta 7.5

Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an org.springframework.core.io.Resource. A malicious user (or attacker) can add a range header with a high number of ranges, or with wide ranges that overlap, or both, for a denial of service attack. This vulnerability affects applications that depend on either spring-webmvc or spring-webflux. Such applications must also have a registration for serving static resources (e.g. JS, CSS, images, and others), or have an annotated controller that returns an org.springframework.core.io.Resource. Spring Boot applications that depend on spring-boot-starter-web or spring-boot-starter-webflux are ready to serve static resources out of the box and are therefore vulnerable.

Prodotti e versioni affette

debian debian_linux
oracle agile_plm
oracle communications_brm_-_elastic_charging_engine
oracle communications_converged_application_server_-_service_controller
oracle communications_diameter_signaling_router
oracle communications_element_manager
oracle communications_online_mediation_controller
oracle communications_session_report_manager
oracle communications_session_route_manager
oracle communications_unified_inventory_management
oracle endeca_information_discovery_integrator
oracle enterprise_manager_for_fusion_applications
oracle enterprise_manager_ops_center
oracle financial_services_analytical_applications_infrastructure · 8.0.2 → 8.0.8
oracle flexcube_private_banking
oracle goldengate_application_adapters
oracle healthcare_master_person_index
oracle identity_manager_connector
oracle insurance_calculation_engine
oracle insurance_policy_administration_j2ee
oracle insurance_rules_palette
oracle mysql_enterprise_monitor · … → 4.0.12
oracle mysql_enterprise_monitor · 8.0.0 → 8.0.20
oracle primavera_analytics
oracle primavera_gateway
oracle rapid_planning
oracle retail_advanced_inventory_planning
oracle retail_assortment_planning
oracle retail_clearance_optimization_engine
oracle retail_financial_integration
oracle retail_integration_bus
oracle retail_invoice_matching
oracle retail_markdown_optimization
oracle retail_order_broker
oracle retail_predictive_application_server
oracle retail_service_backbone
oracle retail_xstore_point_of_service
oracle tape_library_acsls
oracle webcenter_sites
oracle weblogic_server
vmware spring_framework
vmware spring_framework · 4.2.0 → 4.3.20
vmware spring_framework · 5.0.0 → 5.0.10

Analisi

Questa pagina non è ancora indicizzabile.Finché non contiene un’analisi originale — cosa espone davvero, come verificare in due minuti se un sistema è stato toccato, cosa fare se lo è stato — la pagina resta noindex. È il database a deciderlo, non il modello di pagina.

Riferimenti