CSRF Attack via CORS Preflight Requests with Spring MVC or Spring WebFlux
Published Jan 17, 2020
5.3
MEDIUMCVSS 3.1
EPSS 2.43%
Description
Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail authentication. However a notable exception to this are Chrome based browsers when using client certificates for authentication since Chrome sends TLS client certificates in CORS preflight requests in violation of spec requirements. No HTTP body can be sent or received as a result of this attack.
Affected products
-
- Version 5.2StatusaffectedConstraints<v5.2.3.RELEASE
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Spring | Spring Framework | n/a |
|
Configuration 1
- ≥ 5.2.0 · < 5.2.3
Configuration 2
- 13.3.0.1
- 11.3
- 12.0
- ≥ 8.0.0 · ≤ 8.2.2
- 8.1.1
- 8.2.0
- 8.2.1
- 12.5.0
- 8.1.1
- 8.2.0
- 8.2.1
- 13.2.1.0
- 8.0.9.2.0
- 12.0.0
- 12.1.0
- 4.0.2
- ≥ 11.0.0 · ≤ 11.3.1
- 10.2.0
- 10.2.4
- 11.0.2
- 11.1.0
- 11.2.0
- 10.2.0
- 10.2.4
- 11.0.2
- 11.1.0
- 11.2.0
- ≥ 4.0.0 · ≤ 4.0.12
- ≥ 8.0.0 · ≤ 8.0.20
- 12.1
- 12.2
- 15.0
- 16.0
- 14.1
- 14.1
- 15.0
- 16.0
- 15.0.3
- 16.0.3
- 15.0
- 16.0
- 14.1
- 14.0.3
- 14.1.3
- 15.0.3.0
- 16.0.3.0
- 14.1
- 15.0
- 16.0
- 12.2.1.3.0
- 12.2.1.4.0
No data.
Red Hat Fuse 7
springframework
Not affected
Red Hat JBoss BRMS 5
springframework
Out of support scope
Red Hat JBoss Data Virtualization 6
springframework
Out of support scope
Red Hat JBoss Fuse 6
springframework
Out of support scope
Red Hat JBoss Fuse Service Works 6
springframework
Out of support scope
Red Hat JBoss SOA Platform 5
springframework
Out of support scope
Red Hat Storage 3
rhevm-dependencies
Not affected
Red Hat Virtualization 4
rhvm-dependencies
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 7 | springframework | Not affected | n/a |
| Red Hat JBoss BRMS 5 | springframework | Out of support scope | n/a |
| Red Hat JBoss Data Virtualization 6 | springframework | Out of support scope | n/a |
| Red Hat JBoss Fuse 6 | springframework | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | springframework | Out of support scope | n/a |
| Red Hat JBoss SOA Platform 5 | springframework | Out of support scope | n/a |
| Red Hat Storage 3 | rhevm-dependencies | Not affected | n/a |
| Red Hat Virtualization 4 | rhvm-dependencies | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect the version of SpringFramework (embedded in rhevm-dependencies) shipped with Red Hat Gluster Storage 3, as it does not provide support for spring-web. This issue does not affect the version of SpringFramework (embedded in rhvm-dependencies) shipped with Red Hat Virtualization, as it does not provide support for spring-web.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
AV:N/AC:H/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (20 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.43% (0.02428) | 83.64th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.36% (0.02363) | 81.52th | v5 (v2026.06.15) |
| Mar 30, 2025 | 1.17% (0.01170) | 76.72th | v4 (v2025.03.14) |
| Mar 29, 2025 | 21.23% (0.21231) | 92.94th | v4 (v2025.03.14) |
| Mar 24, 2025 | 1.17% (0.01170) | 76.69th | v4 (v2025.03.14) |
| Mar 23, 2025 | 5.75% (0.05752) | 88.73th | v4 (v2025.03.14) |
| Jul 20, 2024 | 0.14% (0.00141) | 50.25th | v3 (v2023.03.01) |
| Dec 24, 2023 | 0.14% (0.00141) | 49.72th | v3 (v2023.03.01) |
| Dec 8, 2023 | 0.12% (0.00123) | 46.37th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.13% (0.00128) | 45.83th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.11% (0.01108) | 55.18th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.11% (0.01108) | 51.54th | v2 (v2022.01.01) |
| Feb 4, 2022 | 10.74% (0.10742) | 87.74th | v2 (v2022.01.01) |
| Feb 3, 2022 | 6.57% (0.06572) | 82.64th | v1 |
| Jan 6, 2022 | 6.57% (0.06572) | 82.47th | v1 |
| Jan 5, 2022 | 1.54% (0.01543) | 73.62th | v5 (v2026.06.15) |
| Oct 21, 2021 | 1.54% (0.01543) | 73.11th | v1 |
| Sep 1, 2021 | 1.32% (0.01324) | 69.73th | v1 |
| Jul 21, 2021 | 1.32% (0.01324) | 0.00th | v1 |
| Apr 14, 2021 | 1.10% (0.01105) | 0.00th | v1 |
References (14)
- https://access.redhat.com/security/cve/CVE-2020-5397 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1800617 Issue Tracking
- https://github.com/advisories/GHSA-7pm4-g2qj-j85x Advisory
- https://github.com/spring-projects/spring-framework
- https://github.com/spring-projects/spring-framework/commit/bc7d01048579430b4b2df668178809b63d3f1929
- https://nvd.nist.gov/vuln/detail/CVE-2020-5397
- https://pivotal.io/security/cve-2020-5397 x_refsource_CONFIRMExploitVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-5397
- https://www.oracle.com//security-alerts/cpujul2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2020.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2020.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujul2022.html x_refsource_MISC
- https://www.oracle.com/security-alerts/cpuoct2020.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.html x_refsource_MISCPatchThird Party Advisory
Change history (0)
No recorded changes yet.