Back

HIGH

Framework: Information (internal server information, classpath, local working directories, session IDs) disclosure

Published Dec 5, 2012

Description

VMware SpringSource Spring Framework before 2.5.6.SEC03, 2.5.7.SR023, and 3.x before 3.0.6, when a container supports Expression Language (EL), evaluates EL expressions in tags twice, which allows remote attackers to obtain sensitive information via a (1) name attribute in a (a) spring:hasBindErrors tag; (2) path attribute in a (b) spring:bind or (c) spring:nestedpath tag; (3) arguments, (4) code, (5) text, (6) var, (7) scope, or (8) message attribute in a (d) spring:message or (e) spring:theme tag; or (9) var, (10) scope, or (11) value attribute in a (f) spring:transform tag, aka "Expression Language Injection."

Affected products

Remediation

Red Hat statement

This flaw was originally reported as resulting in information disclosure only, and was therefore assessed as having low security impact. On this basis, it was planned that future updates to JBoss products may address this flaw. New research [0] has now shown that this flaw can lead to remote code execution. The security impact has been re-assessed as important, and Red Hat is now working on patches for all affected products. [0] http://danamodio.com/application-security/discoveries/spring-remote-code-with-expression-language-injection/

Metrics

Weaknesses (1)

References (27)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 5, 2012
Updated Aug 6, 2024
Reserved Jul 11, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity Important
Public date Sep 9, 2011
GHSA-WV88-PF73-X22P