Open Redirect Vulnerability in fp2952 Spring Cloud Base from Vendor
CVE-2025-4328
What is CVE-2025-4328?
A vulnerability exists in the HTTP Header Handler component of the fp2952 Spring Cloud Base. This issue arises from improper validation of the 'Referer' argument in the sendBack function located in MvcController.java. The vulnerability allows an attacker to execute an open redirect, potentially leading users to malicious sites. As this flaw can be exploited remotely, it poses a significant risk to users. The product's approach of rolling releases complicates tracking affected versions, as continual updates are made without specific version numbers indicated.
Affected Version(s)
spring-cloud-base 7f050dc6db9afab82c5ce1d41cd74ed255ec9bfa
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved