4.3
CVSSv2

CVE-2011-2732

Published: 05/12/2012 Updated: 06/12/2012
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

CRLF injection vulnerability in the logout functionality in VMware SpringSource Spring Security prior to 2.0.7 and 3.0.x prior to 3.0.6 allows remote malicious users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the spring-security-redirect parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

vmware springsource spring security 3.0.1

vmware springsource spring security 3.0.2

vmware springsource spring security 3.0.3

vmware springsource spring security 3.0.4

vmware springsource spring security

vmware springsource spring security 2.0.4

vmware springsource spring security 3.0.0

vmware springsource spring security 2.0.0

vmware springsource spring security 2.0.1

vmware springsource spring security 2.0.2

vmware springsource spring security 2.0.3

vmware springsource spring security 2.0.5

Vendor Advisories

Debian Bug report logs - #670901 Spring: Multiple security issues Package: libspring-security-20-java; Maintainer for libspring-security-20-java is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <muehlenhoff@univentionde> Date: Mon, 30 Apr 2012 07:57:05 UTC ...

Exploits

source: wwwsecurityfocuscom/bid/49535/info Spring Security is prone to a vulnerability that allows attackers to inject arbitrary HTTP headers because it fails to sufficiently sanitize input By inserting arbitrary headers into an HTTP response, attackers may be able to launch various attacks, including cross-site request forgery, cross-s ...
Spring Security allows the use of a parameter (named "spring-security-redirect" by default) to determine the location URL to which a user will be redirected after logging in This will normally be submitted as part of the login request, so is deemed to be an acceptable use of remote supplied data However, the functionality is in a base class which ...