Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0493 | Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote client, and then uses that input to make a multipart request to another server (server B), it can be exposed to an attack, where an extra multipart is inserted in the content of the request from server A, causing server B to use the wrong value for a part it expects. This could to lead privilege escalation, for example, if the part content represents a username or user roles. |
Github GHSA |
GHSA-4487-x383-qpph | Possible privilege escalation in org.springframework:spring-core |
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Subscriptions
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-17T02:15:49.301Z
Reserved: 2017-12-06T00:00:00.000Z
Link: CVE-2018-1272
No data.
Status : Modified
Published: 2018-04-06T13:29:00.563
Modified: 2026-06-17T01:50:53.350
Link: CVE-2018-1272
OpenCVE Enrichment
No data.
-
CWE-88
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
- NVD-CWE-noinfo
EUVD
Github GHSA