Cross-Site Request Forgery Vulnerability in Spring Framework by Pivotal
CVE-2015-5258
8.8HIGH
What is CVE-2015-5258?
The Spring Framework is susceptible to a Cross-Site Request Forgery (CSRF) vulnerability which can allow an attacker to perform unauthorized actions on behalf of an authenticated user without their knowledge. This occurs when an attacker tricks a user into submitting a malicious request via the web browser, potentially compromising sensitive data or making changes to their account settings. Users should ensure they have updated to version 1.1.3 or higher to mitigate this risk.