Cross-site tracing attack in Spring Framework - CVE-2018-11039

 

Cross-site tracing attack in Spring Framework - CVE-2018-11039

Published: June 26, 2018 / Updated: June 27, 2018


Vulnerability identifier: #VU13499
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-11039
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The disclosed vulnerability allows a remote attacker to perform cross-site tracing (XST) attacks.

The vulnerability exists due to the HiddenHttpMethodFilter class in the Spring MVC framework used by the affected software allows web applications to change the HTTP request method to any HTTP method, including the TRACE method. A remote attacker can trick a user who is using a web application that has a cross-site scripting (XSS) vulnerability into following a link that submits malicious input, conduct an XST attack and access sensitive information, such as the user's credentials. 

Successful exploitation of the vulnerability results in information disclosure.


Affected software

Spring Framework
Dell Support Assist Enterprise
IBM Cognos Controller

How to mitigate CVE-2018-11039

Update to version 4.3.18, 5.0.7.

Spring Framework - addressed in versions 4.3.18, 5.0.7
Dell Support Assist Enterprise - update to 4.00.06.00
IBM Cognos Controller - addressed in versions 10.4.1.0.15, 10.4.2.0.2

External References

Related Security Bulletins