VulnerabilityModified
CVE-2014-1904
Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the requested URI in a default…
MEDIUM 4.3EPSS 6.90%
Does this matter?
Lower severity and a low EPSS score (6.90%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the requested URI in a default action.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 6.90% probability · 94th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- pivotal software/spring framework
- Source
- cve@mitre.org
References
- http://docs.spring.io/spring/docs/3.2.8.RELEASE/changelog.txtVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0400.htmlThird Party Advisory
- http://seclists.org/fulldisclosure/2014/Mar/101Mailing List, Third Party Advisory
- http://secunia.com/advisories/57915Permissions Required
- http://www.gopivotal.com/security/cve-2014-1904Patch, Vendor Advisory
- http://www.securityfocus.com/archive/1/531422/100/0/threadedBroken Link
- http://www.securityfocus.com/bid/66137Third Party Advisory, VDB Entry
- https://github.com/spring-projects/spring-framework/commit/741b4b229ae032bd17175b46f98673ce0bd2d485Patch, Third Party Advisory
- https://jira.springsource.org/browse/SPR-11426Permissions Required
- http://docs.spring.io/spring/docs/3.2.8.RELEASE/changelog.txtVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0400.htmlThird Party Advisory
- http://seclists.org/fulldisclosure/2014/Mar/101Mailing List, Third Party Advisory
- http://secunia.com/advisories/57915Permissions Required
- http://www.gopivotal.com/security/cve-2014-1904Patch, Vendor Advisory
- http://www.securityfocus.com/archive/1/531422/100/0/threadedBroken Link
- http://www.securityfocus.com/bid/66137Third Party Advisory, VDB Entry
- https://github.com/spring-projects/spring-framework/commit/741b4b229ae032bd17175b46f98673ce0bd2d485Patch, Third Party Advisory
- https://jira.springsource.org/browse/SPR-11426Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.