Cross-Site Request Forgery Vulnerability in Pivotal Spring Batch Admin
CVE-2018-1230

8.8HIGH

Key Information:

Vendor
CVE Published:
21 March 2018

What is CVE-2018-1230?

Pivotal Spring Batch Admin is vulnerable to cross-site request forgery, allowing remote unauthenticated users to craft malicious sites that execute unauthorized requests to the application. This vulnerability arises from the absence of CSRF protection. As Spring Batch Admin has reached its end of life, no patches are available to mitigate these risks, leaving installations exposed to potential exploitation.

Affected Version(s)

Spring Batch Admin All

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2018-1230 : Cross-Site Request Forgery Vulnerability in Pivotal Spring Batch Admin