Multipart Request Vulnerability in Spring Framework by Pivotal
CVE-2018-1272
What is CVE-2018-1272?
The Spring Framework, specifically versions 5.0 prior to 5.0.5 and 4.3 prior to 4.3.15, is susceptible to a multipart request vulnerability. This issue arises when a Spring MVC or Spring WebFlux server application (referred to as server A) processes input from a client and uses that input to create a multipart request to another server (server B). An attacker may exploit this vulnerability by inserting an additional multipart into the request's content from server A. If server B relies on the part content for critical information, such as usernames or user roles, this can lead to unauthorized privilege escalation, undermining application security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Spring Framework Versions prior to 5.0.5 and 4.3.15
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
