spring-webflow: Data Binding Expression Vulnerability in Spring Web Flow
Published Nov 27, 2017
5.9
MEDIUMCVSS 3.0
EPSS 0.96%
Description
An issue was discovered in Pivotal Spring Web Flow through 2.4.5. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that process form submissions but do not have a sub-element to declare explicit data binding property mappings. NOTE: this issue exists because of an incomplete fix for CVE-2017-4971.
Affected products
No data.
- 2.4.0
- 2.4.1
- 2.4.2
- 2.4.4
- 2.4.5
No data.
Red Hat Enterprise Virtualization 3
jasperreports-server-pro
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Virtualization 3 | jasperreports-server-pro | Will not fix | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the versions of spring-webflow as shipped with Red Hat Enterprise Virtualization 3. Red Hat Product Security has rated this issue as having (Low|Moderate) security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
1 other source (Red Hat) ▾
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L
AV:N/AC:M/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
Table of values (9 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.96% (0.00963) | 60.27th | v5 (v2026.06.15) |
| Sep 20, 2026 | 0.96% (0.00963) | 60.13th | v5 (v2026.06.15) |
| Jul 20, 2024 | 0.17% (0.00173) | 54.86th | v3 (v2023.03.01) |
| Sep 3, 2023 | 0.17% (0.00171) | 53.55th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.18% (0.00179) | 53.29th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.89% (0.00885) | 27.89th | v2 (v2022.01.01) |
| Feb 4, 2022 | 0.89% (0.00885) | 10.50th | v2 (v2022.01.01) |
| Feb 3, 2022 | 0.66% (0.00663) | 18.75th | v5 (v2026.06.15) |
| Apr 14, 2021 | 0.66% (0.00663) | 0.00th | v1 |
References (7)
- http://www.securityfocus.com/bid/100849 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2017-8039 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1494413 Issue Tracking
- https://github.com/advisories/GHSA-q4v9-qjmw-j7vf Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-8039
- https://pivotal.io/security/cve-2017-8039 x_refsource_CONFIRMIssue TrackingMitigationVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2017-8039
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/100849 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2017-8039 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1494413 | Issue Tracking | |
| https://github.com/advisories/GHSA-q4v9-qjmw-j7vf | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-8039 | ||
| https://pivotal.io/security/cve-2017-8039 | x_refsource_CONFIRMIssue TrackingMitigationVendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2017-8039 |
Change history (0)
No recorded changes yet.