Red Hat Bugzilla – Bug 1591929
CVE-2018-11039 springframework: Cross Site Tracing (XST) if vulnerable to XSS
Last modified: 2018-10-18 09:06:28 EDT
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack. References: https://pivotal.io/security/cve-2018-11039
Created springframework tracking bugs for this issue: Affects: fedora-all [bug 1591930]