CVE-2011-2730
Vulnerability Summary
Timeline
Description
VMware SpringSource Spring Framework before 2.5.6.SEC03, 2.5.7.SR023, and 3.x before 3.0.6, when a container supports Expression Language (EL), evaluates EL expressions in tags twice, which allows remote attackers to obtain sensitive information via a (1) name attribute in a (a) spring:hasBindErrors tag; (2) path attribute in a (b) spring:bind or (c) spring:nestedpath tag; (3) arguments, (4) code, (5) text, (6) var, (7) scope, or (8) message attribute in a (d) spring:message or (e) spring:theme tag; or (9) var, (10) scope, or (11) value attribute in a (f) spring:transform tag, aka "Expression Language Injection."
CVSS Metrics
- v2.0•HIGH•Score: 7.5AV:N/AC:L/Au:N/C:P/I:P/A:P
EPSS Trends
Current EPSS score: 46.31%• Percentile: 98%
Techniques & Countermeasures
- CWE-16•Configuration
Weaknesses in this category are typically introduced during the configuration of the software.
Affected Systems
- org.springframework•spring-core
≥ 3.0.0, < 3.0.6 | < 2.5.6.SEC03 | ≥ 2.5.7.SR0, < 2.5.7.SR023
- springsource•spring_framework
≤ 2.5.7_sr01 | ≤ 3.0.5 | 2.5.0 | 2.5.0:rc1 | 2.5.0:rc2 | 2.5.1 | 2.5.2 | 2.5.3 | 2.5.4 | 2.5.5 | 2.5.6 | 2.5.7 | 3.0.0 | 3.0.1 | 3.0.2 | 3.0.3 | 3.0.4
References (24)
- http://support.springsource.com/security/cve-2011-2730
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=677814
- http://rhn.redhat.com/errata/RHSA-2013-0192.html
- http://rhn.redhat.com/errata/RHSA-2013-0198.html
- http://rhn.redhat.com/errata/RHSA-2013-0195.html
- http://rhn.redhat.com/errata/RHSA-2013-0221.html
- http://www.debian.org/security/2012/dsa-2504
- http://rhn.redhat.com/errata/RHSA-2013-0196.html
- http://secunia.com/advisories/55155
- http://rhn.redhat.com/errata/RHSA-2013-0193.html
- http://secunia.com/advisories/51984
- http://secunia.com/advisories/52054
- http://rhn.redhat.com/errata/RHSA-2013-0191.html
- http://rhn.redhat.com/errata/RHSA-2013-0533.html
- http://rhn.redhat.com/errata/RHSA-2013-0197.html
- http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html
- http://www.securitytracker.com/id/1029151
- http://rhn.redhat.com/errata/RHSA-2013-0194.html
- https://docs.google.com/document/d/1dc1xxO8UMFaGLOwgkykYdghGWm_2Gn0iCrxFsympqcE/edit
- https://nvd.nist.gov/vuln/detail/CVE-2011-2730
- https://github.com/spring-projects/spring-framework/commit/62ccc8dd7e645fb91705d44919abac838cb5ca3f
- https://github.com/spring-projects/spring-framework/commit/9772eb8410e37cd0bdec0d1b133218446c778beb
- https://github.com/spring-projects/spring-framework/commit/b8d86330d1fadc645630416c3aaebf131bf749fc
- https://github.com/spring-projects/spring-framework