CVE-2024-22259

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Mar 16, 2024
Updated: Jul 3, 2024
CWE ID 601

Summary

CVE-2024-22259 is a cybersecurity vulnerability affecting applications that utilize UriComponentsBuilder in the Spring Framework for URL parsing and validation. Applications exposed to externally provided URLs, such as those passed through query parameters, are susceptible to open redirect attacks or Server Side Request Forgery (SSRF). This issue is distinct from CVE-2024-22243, but involves different input. (Open Redirect refers to an attack where an attacker tricks a victim into clicking a malicious link, which then redirects the user to an attacker-controlled page. SSRF attacks allow an attacker to make unauthorized requests to internal resources on the targeted system.)

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Vmware Spring Framework

Affected Vendors

  • VMware Inc.