CVE-2020-5397 (CNNVD-202001-841)
中文标题:
Pivotal Software Spring Framework 跨站请求伪造漏洞
英文标题:
CSRF Attack via CORS Preflight Requests with Spring MVC or Spring WebFlux
漏洞描述
中文描述:
Pivotal Software Spring Framework是美国Pivotal Software公司的一套开源的Java、JavaEE应用程序框架。该框架可帮助开发人员构建高质量的应用。 Pivotal Software Spring Framework 5.2.3之前的5.2.x版本中存在跨站请求伪造漏洞。该漏洞源于WEB应用未充分验证请求是否来自可信用户。攻击者可利用该漏洞通过受影响客户端向服务器发送非预期的请求。
英文描述:
Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail authentication. However a notable exception to this are Chrome based browsers when using client certificates for authentication since Chrome sends TLS client certificates in CORS preflight requests in violation of spec requirements. No HTTP body can be sent or received as a result of this attack.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| Spring | Spring Framework | - | < v5.2.3.RELEASE | - |
cpe:2.3:a:spring:spring_framework:*:*:*:*:*:*:*:*
|
| vmware | spring_framework | * | - | - |
cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*
|
| oracle | application_testing_suite | 13.3.0.1 | - | - |
cpe:2.3:a:oracle:application_testing_suite:13.3.0.1:*:*:*:*:*:*:*
|
| oracle | communications_brm_-_elastic_charging_engine | 11.3 | - | - |
cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:11.3:*:*:*:*:*:*:*
|
| oracle | communications_brm_-_elastic_charging_engine | 12.0 | - | - |
cpe:2.3:a:oracle:communications_brm_-_elastic_charging_engine:12.0:*:*:*:*:*:*:*
|
| oracle | communications_diameter_signaling_router | * | - | - |
cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:*
|
| oracle | communications_element_manager | 8.1.1 | - | - |
cpe:2.3:a:oracle:communications_element_manager:8.1.1:*:*:*:*:*:*:*
|
| oracle | communications_element_manager | 8.2.0 | - | - |
cpe:2.3:a:oracle:communications_element_manager:8.2.0:*:*:*:*:*:*:*
|
| oracle | communications_element_manager | 8.2.1 | - | - |
cpe:2.3:a:oracle:communications_element_manager:8.2.1:*:*:*:*:*:*:*
|
| oracle | communications_policy_management | 12.5.0 | - | - |
cpe:2.3:a:oracle:communications_policy_management:12.5.0:*:*:*:*:*:*:*
|
| oracle | communications_session_route_manager | 8.1.1 | - | - |
cpe:2.3:a:oracle:communications_session_route_manager:8.1.1:*:*:*:*:*:*:*
|
| oracle | communications_session_route_manager | 8.2.0 | - | - |
cpe:2.3:a:oracle:communications_session_route_manager:8.2.0:*:*:*:*:*:*:*
|
| oracle | communications_session_route_manager | 8.2.1 | - | - |
cpe:2.3:a:oracle:communications_session_route_manager:8.2.1:*:*:*:*:*:*:*
|
| oracle | enterprise_manager_base_platform | 13.2.1.0 | - | - |
cpe:2.3:a:oracle:enterprise_manager_base_platform:13.2.1.0:*:*:*:*:*:*:*
|
| oracle | financial_services_regulatory_reporting_with_agilereporter | 8.0.9.2.0 | - | - |
cpe:2.3:a:oracle:financial_services_regulatory_reporting_with_agilereporter:8.0.9.2.0:*:*:*:*:*:*:*
|
| oracle | flexcube_private_banking | 12.0.0 | - | - |
cpe:2.3:a:oracle:flexcube_private_banking:12.0.0:*:*:*:*:*:*:*
|
| oracle | flexcube_private_banking | 12.1.0 | - | - |
cpe:2.3:a:oracle:flexcube_private_banking:12.1.0:*:*:*:*:*:*:*
|
| oracle | healthcare_master_person_index | 4.0.2 | - | - |
cpe:2.3:a:oracle:healthcare_master_person_index:4.0.2:*:*:*:*:*:*:*
|
| oracle | insurance_calculation_engine | * | - | - |
cpe:2.3:a:oracle:insurance_calculation_engine:*:*:*:*:*:*:*:*
|
| oracle | insurance_policy_administration_j2ee | 10.2.0 | - | - |
cpe:2.3:a:oracle:insurance_policy_administration_j2ee:10.2.0:*:*:*:*:*:*:*
|
| oracle | insurance_policy_administration_j2ee | 10.2.4 | - | - |
cpe:2.3:a:oracle:insurance_policy_administration_j2ee:10.2.4:*:*:*:*:*:*:*
|
| oracle | insurance_policy_administration_j2ee | 11.0.2 | - | - |
cpe:2.3:a:oracle:insurance_policy_administration_j2ee:11.0.2:*:*:*:*:*:*:*
|
| oracle | insurance_policy_administration_j2ee | 11.1.0 | - | - |
cpe:2.3:a:oracle:insurance_policy_administration_j2ee:11.1.0:*:*:*:*:*:*:*
|
| oracle | insurance_policy_administration_j2ee | 11.2.0 | - | - |
cpe:2.3:a:oracle:insurance_policy_administration_j2ee:11.2.0:*:*:*:*:*:*:*
|
| oracle | insurance_rules_palette | 10.2.0 | - | - |
cpe:2.3:a:oracle:insurance_rules_palette:10.2.0:*:*:*:*:*:*:*
|
| oracle | insurance_rules_palette | 10.2.4 | - | - |
cpe:2.3:a:oracle:insurance_rules_palette:10.2.4:*:*:*:*:*:*:*
|
| oracle | insurance_rules_palette | 11.0.2 | - | - |
cpe:2.3:a:oracle:insurance_rules_palette:11.0.2:*:*:*:*:*:*:*
|
| oracle | insurance_rules_palette | 11.1.0 | - | - |
cpe:2.3:a:oracle:insurance_rules_palette:11.1.0:*:*:*:*:*:*:*
|
| oracle | insurance_rules_palette | 11.2.0 | - | - |
cpe:2.3:a:oracle:insurance_rules_palette:11.2.0:*:*:*:*:*:*:*
|
| oracle | mysql_enterprise_monitor | * | - | - |
cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*
|
| oracle | rapid_planning | 12.1 | - | - |
cpe:2.3:a:oracle:rapid_planning:12.1:*:*:*:*:*:*:*
|
| oracle | rapid_planning | 12.2 | - | - |
cpe:2.3:a:oracle:rapid_planning:12.2:*:*:*:*:*:*:*
|
| oracle | retail_assortment_planning | 15.0 | - | - |
cpe:2.3:a:oracle:retail_assortment_planning:15.0:*:*:*:*:*:*:*
|
| oracle | retail_assortment_planning | 16.0 | - | - |
cpe:2.3:a:oracle:retail_assortment_planning:16.0:*:*:*:*:*:*:*
|
| oracle | retail_back_office | 14.1 | - | - |
cpe:2.3:a:oracle:retail_back_office:14.1:*:*:*:*:*:*:*
|
| oracle | retail_central_office | 14.1 | - | - |
cpe:2.3:a:oracle:retail_central_office:14.1:*:*:*:*:*:*:*
|
| oracle | retail_financial_integration | 15.0 | - | - |
cpe:2.3:a:oracle:retail_financial_integration:15.0:*:*:*:*:*:*:*
|
| oracle | retail_financial_integration | 16.0 | - | - |
cpe:2.3:a:oracle:retail_financial_integration:16.0:*:*:*:*:*:*:*
|
| oracle | retail_integration_bus | 15.0.3 | - | - |
cpe:2.3:a:oracle:retail_integration_bus:15.0.3:*:*:*:*:*:*:*
|
| oracle | retail_integration_bus | 16.0.3 | - | - |
cpe:2.3:a:oracle:retail_integration_bus:16.0.3:*:*:*:*:*:*:*
|
| oracle | retail_order_broker | 15.0 | - | - |
cpe:2.3:a:oracle:retail_order_broker:15.0:*:*:*:*:*:*:*
|
| oracle | retail_order_broker | 16.0 | - | - |
cpe:2.3:a:oracle:retail_order_broker:16.0:*:*:*:*:*:*:*
|
| oracle | retail_point-of-service | 14.1 | - | - |
cpe:2.3:a:oracle:retail_point-of-service:14.1:*:*:*:*:*:*:*
|
| oracle | retail_predictive_application_server | 14.0.3 | - | - |
cpe:2.3:a:oracle:retail_predictive_application_server:14.0.3:*:*:*:*:*:*:*
|
| oracle | retail_predictive_application_server | 14.1.3 | - | - |
cpe:2.3:a:oracle:retail_predictive_application_server:14.1.3:*:*:*:*:*:*:*
|
| oracle | retail_predictive_application_server | 15.0.3.0 | - | - |
cpe:2.3:a:oracle:retail_predictive_application_server:15.0.3.0:*:*:*:*:*:*:*
|
| oracle | retail_predictive_application_server | 16.0.3.0 | - | - |
cpe:2.3:a:oracle:retail_predictive_application_server:16.0.3.0:*:*:*:*:*:*:*
|
| oracle | retail_returns_management | 14.1 | - | - |
cpe:2.3:a:oracle:retail_returns_management:14.1:*:*:*:*:*:*:*
|
| oracle | retail_service_backbone | 15.0 | - | - |
cpe:2.3:a:oracle:retail_service_backbone:15.0:*:*:*:*:*:*:*
|
| oracle | retail_service_backbone | 16.0 | - | - |
cpe:2.3:a:oracle:retail_service_backbone:16.0:*:*:*:*:*:*:*
|
| oracle | weblogic_server | 12.2.1.3.0 | - | - |
cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:*
|
| oracle | weblogic_server | 12.2.1.4.0 | - | - |
cpe:2.3:a:oracle:weblogic_server:12.2.1.4.0:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
3.0 (cna)
MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2020-5397 |
2025-11-11 15:20:39 | 2025-11-11 07:36:24 |
| NVD | nvd_CVE-2020-5397 |
2025-11-11 14:56:55 | 2025-11-11 07:44:47 |
| CNNVD | cnnvd_CNNVD-202001-841 |
2025-11-11 15:10:21 | 2025-11-11 07:55:24 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 跨站请求伪造
- cnnvd_id: 未提取 -> CNNVD-202001-841
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- affected_products_count: 1 -> 52
- data_sources: ['cve'] -> ['cve', 'nvd']