CVE-2020-5421 vulnerability in Pivotal Software and Other Products
Published on September 19, 2020
RFD Protection Bypass via jsessionid
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
Products Associated with CVE-2020-5421
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2020-5421 are published in these products:
Affected Versions
Spring by VMware Spring Framework:- Version 4.3 and below 4.3.29 is affected.
- Version 5.0 and below 5.0.19 is affected.
- Version 5.1 and below 5.1.18 is affected.
- Version 5.2 and below 5.2.9 is affected.
Exploit Probability
EPSS
63.83%
Percentile
98.38%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.