Informazioni sul CVE-2018-1258
N/A
CWE ID: N/A
Base Score (CVSS): N/A
CVE: CVE-2018-1258
Descrizione: Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
Vettore di attacco
Punteggio CVSS
Il CVSS è un sistema di valutazione che misura la gravità di una vulnerabilità informatica considerando fattori come l’impatto potenziale, la probabilità di attacco e la facilità di esecuzione.
Punteggio Base (calcolato da AziendaSicura): 0.0 (None)
Riassunto: .
Dettaglio del Vettore
Metrica | Valore | Significato | Descrizione |
---|
Riferimenti esterni
- http://www.securityfocus.com/bid/104222
- http://www.securitytracker.com/id/1041888
- http://www.securitytracker.com/id/1041896
- https://access.redhat.com/errata/RHSA-2019:2413
- https://www.oracle.com/security-alerts/cpuapr2020.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
- http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html
- https://www.oracle.com/security-alerts/cpujul2020.html
- https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html
- https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
- https://www.oracle.com/security-alerts/cpujan2020.html
- https://security.netapp.com/advisory/ntap-20181018-0002/
- https://pivotal.io/security/cve-2018-1258
- https://www.oracle.com/security-alerts/cpujan2021.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
Prodotti interessati
- Pivotal – Spring Framework
Relazioni con altri prodotti
Produttore:Pivotal
Prodotto: Spring Framework
Anno: 2018
CWE:
CVSS: 0.0