Cross-Site Request Forgery Vulnerability in Spring Batch Admin by Spring
CVE-2017-12881

8.8HIGH

Key Information:

Vendor
CVE Published:
18 August 2017

What is CVE-2017-12881?

A cross-site request forgery (CSRF) vulnerability exists in Spring Batch Admin prior to version 1.3.0. This vulnerability enables remote attackers to potentially hijack user authentication and issue unauthorized requests. By exploiting this flaw, attackers could manipulate the application's functionalities, including the capability to upload files, leading to unauthorized access and control over the system.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2017-12881 : Cross-Site Request Forgery Vulnerability in Spring Batch Admin by Spring