CyberRota Analysis
AI-GeneratedSpring MVC applications utilizing UrlFileNameViewController without a configured prefix are susceptible to open redirect vulnerabilities, allowing attackers to manipulate URLs and potentially redirect users to malicious sites. This issue affects multiple versions of the Spring Framework, specifically from 5.2.25.RELEASE up to 7.0.8. Organizations using these versions should prioritize remediation to mitigate the risk of phishing attacks and unauthorized access.
Original NVD Description
A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
Related CVEs
Other vulnerabilities affecting the same vendor(s)