CVE-2026-40985
- EPSS 0.23%
- Veröffentlicht 11.06.2026 05:16:33
- Zuletzt bearbeitet 04.09.2026 18:12:31
Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through 2.5.1.
CVE-2026-40986
- EPSS 0.2%
- Veröffentlicht 11.06.2026 05:03:26
- Zuletzt bearbeitet 04.09.2026 18:11:51
Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if the error response from the server contains error de...
CVE-2017-8039
- EPSS 0.96%
- Veröffentlicht 27.11.2017 10:29:00
- Zuletzt bearbeitet 08.09.2026 17:13:05
An issue was discovered in Pivotal Spring Web Flow through 2.4.5. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL e...
CVE-2017-4971
- EPSS 15.86%
- Veröffentlicht 13.06.2017 06:29:00
- Zuletzt bearbeitet 08.09.2026 17:13:05
An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL e...