Vulnerability Description
Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the requested URI in a default action.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pivotal Software | Spring Framework | >= 3.0.0, < 3.2.8 |
Related Weaknesses (CWE)
References
- http://docs.spring.io/spring/docs/3.2.8.RELEASE/changelog.txtVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0400.htmlThird Party Advisory
- http://seclists.org/fulldisclosure/2014/Mar/101Mailing ListThird Party Advisory
- http://secunia.com/advisories/57915Permissions Required
- http://www.gopivotal.com/security/cve-2014-1904PatchVendor Advisory
- http://www.securityfocus.com/archive/1/531422/100/0/threadedBroken Link
- http://www.securityfocus.com/bid/66137Third Party AdvisoryVDB Entry
- https://github.com/spring-projects/spring-framework/commit/741b4b229ae032bd17175PatchThird Party Advisory
- https://jira.springsource.org/browse/SPR-11426Permissions Required
- http://docs.spring.io/spring/docs/3.2.8.RELEASE/changelog.txtVendor Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0400.htmlThird Party Advisory
- http://seclists.org/fulldisclosure/2014/Mar/101Mailing ListThird Party Advisory
- http://secunia.com/advisories/57915Permissions Required
- http://www.gopivotal.com/security/cve-2014-1904PatchVendor Advisory
- http://www.securityfocus.com/archive/1/531422/100/0/threadedBroken Link
FAQ
What is CVE-2014-1904?
CVE-2014-1904 is a vulnerability with a CVSS score of 4.3 (MEDIUM). Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject arbitrary w...
How severe is CVE-2014-1904?
CVE-2014-1904 has been rated MEDIUM with a CVSS base score of 4.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-1904?
Check the references section above for vendor advisories and patch information. Affected products include: Pivotal Software Spring Framework.