Open Redirect Vulnerability in fp2952 Spring Cloud Base from Vendor
CVE-2025-4328

5.1MEDIUM

Key Information:

Vendor

Fp2952

Vendor
CVE Published:
6 May 2025

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2025-4328?

A vulnerability exists in the HTTP Header Handler component of the fp2952 Spring Cloud Base. This issue arises from improper validation of the 'Referer' argument in the sendBack function located in MvcController.java. The vulnerability allows an attacker to execute an open redirect, potentially leading users to malicious sites. As this flaw can be exploited remotely, it poses a significant risk to users. The product's approach of rolling releases complicates tracking affected versions, as continual updates are made without specific version numbers indicated.

Affected Version(s)

spring-cloud-base 7f050dc6db9afab82c5ce1d41cd74ed255ec9bfa

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

ShenxiuSecurity (VulDB User)
.