CVE-2018-11040

unknown
Published 2018-10-16 · Modified 2024-05-15
CVSS v3
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v2
VIR risk

Description

Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not enabled by default in Spring Framework nor Spring Boot, however, when MappingJackson2JsonView is configured in an application, JSONP support is automatically ready to use through the "jsonp" and "callback" JSONP parameters, enabling cross-domain requests.

Predictions

Exploit likelihood
30%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2018-11040

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed4.3.19-1
debian debianbullseyefixed4.3.19-1
debian debianforkyfixed4.3.19-1
debian debiansidfixed4.3.19-1
debian debiantrixiefixed4.3.19-1

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.springframework:spring-core>=5.0.0.RELEASE,<5.0.7.RELEASE5.0.7.RELEASE
java Mavenorg.springframework:spring-core>=4.3.0.RELEASE,<4.3.18.RELEASE4.3.18.RELEASE

References

Verify integrity in audit chain (admin only). AS-IS.