RFD Protection Bypass via jsessionid
Published Sep 19, 2020
6.5
MEDIUMCVSS 3.1
EPSS 10.74%
Description
In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.
Affected products
-
- Version 4.3StatusaffectedConstraints<4.3.29
- Version 5.0StatusaffectedConstraints<5.0.19
- Version 5.1StatusaffectedConstraints<5.1.18
- Version 5.2StatusaffectedConstraints<5.2.9
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Spring by VMware | Spring Framework | n/a |
|
Configuration 1
- < 4.3.29
- ≥ 5.0.0 · < 5.0.19
- ≥ 5.1.0 · < 5.1.18
- ≥ 5.2.0 · < 5.2.9
Configuration 2
- 11.3.2
- 11.3.0.9
- 12.0.0.3
- 7.3.4
- 7.3.5
- 7.4.0
- ≥ 8.2.1 · ≤ 8.2.2.1
- 7.3.4
- 7.3.5
- 3.2.0
- 12.2.1.3.0
- 12.2.1.4.0
- ≥ 8.0.6 · ≤ 8.1.0
- 12.0.0
- 12.1.0
- 12.2.1.3.0
- 12.2.1.4.0
- 19.1.0.0.0
- 4.0.2.5
- 11.1.2.4
- ≥ 11.1.0 · ≤ 11.3.0
- 10.2
- 10.2.4
- 11.0.2
- ≥ 11.1.0 · ≤ 11.3.0
- 10.2.0
- 10.2.4
- 11.0.2
- ≤ 8.0.22
- 8.0.23
- ≥ 16.2.0 · ≤ 16.2.11
- ≥ 17.12.0 · ≤ 17.12.9
- ≥ 18.8.0 · ≤ 18.8.10
- ≥ 19.12.0 · ≤ 19.12.10
- ≥ 16.1.0 · ≤ 16.2.20
- ≥ 17.1.0 · ≤ 17.12.19
- ≥ 18.1.0 · ≤ 18.8.21
- ≥ 19.12.0 · ≤ 19.12.10
- 16.0.3.0
- 16.0.3.0
- ≥ 16.0 · ≤ 19.0
- ≥ 16.0 · ≤ 19.0
- 14.1.3
- 15.0.3
- 16.0.3
- 14.1.3
- 15.0.3
- 16.0.3
- 14.0
- 14.1
- 16.0.3
- 15.0
- 16.0
- 14.1
- 14.1
- 14.1.3
- 15.0.3
- 16.0.3
- 15.0.4
- 16.0.6
- 17.0.4
- 18.0.3
- 19.0.2
- 8.5.1
- 2.3
- 10.3.6.0.0
- 12.1.3.0.0
- 12.2.1.3.0
- 12.2.1.4.0
- 14.1.1.0.0
Configuration 3
- n/a
- n/a
- n/a
No data.
Red Hat Fuse 7.9
springframework
Fixed · RHSA-2021:3140
Red Hat JBoss BRMS 5
springframework
Out of support scope
Red Hat JBoss Data Virtualization 6
springframework
Out of support scope
Red Hat JBoss Fuse 6
springframework
Out of support scope
Red Hat JBoss Fuse Service Works 6
springframework
Out of support scope
Red Hat JBoss SOA Platform 5
springframework
Out of support scope
Red Hat Storage 3
rhevm-dependencies
Not affected
Red Hat Virtualization 4
rhvm-dependencies
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 7.9 | springframework | Fixed | RHSA-2021:3140 |
| Red Hat JBoss BRMS 5 | springframework | Out of support scope | n/a |
| Red Hat JBoss Data Virtualization 6 | springframework | Out of support scope | n/a |
| Red Hat JBoss Fuse 6 | springframework | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | springframework | Out of support scope | n/a |
| Red Hat JBoss SOA Platform 5 | springframework | Out of support scope | n/a |
| Red Hat Storage 3 | rhevm-dependencies | Not affected | n/a |
| Red Hat Virtualization 4 | rhvm-dependencies | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect the version of SpringFramework (embedded in rhvm-dependencies) shipped with Red Hat Virtualization, as it does not provide support for spring-web. In Red Hat Gluster Storage 3, SpringFramework (embedded in rhvm-dependencies) was shipped as a part of Red Hat Gluster Storage Console that is no longer supported for use with Red Hat Gluster Storage 3.5. However, spring-web is not included in the shipped version of SpringFramework.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
AV:N/AC:H/Au:S/C:P/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (48 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 10.74% (0.10736) | 95.70th | v5 (v2026.06.15) |
| Jun 15, 2026 | 10.74% (0.10736) | 95.24th | v5 (v2026.06.15) |
| Mar 22, 2026 | 63.83% (0.63828) | 98.40th | v4 (v2025.03.14) |
| Mar 18, 2026 | 68.07% (0.68074) | 98.57th | v4 (v2025.03.14) |
| Jan 14, 2026 | 63.83% (0.63828) | 98.36th | v4 (v2025.03.14) |
| Dec 14, 2025 | 56.17% (0.56167) | 97.99th | v4 (v2025.03.14) |
| Nov 21, 2025 | 63.83% (0.63828) | 98.32th | v4 (v2025.03.14) |
| Nov 18, 2025 | 75.67% (0.75673) | 98.98th | v4 (v2025.03.14) |
| Oct 15, 2025 | 63.83% (0.63828) | 98.32th | v4 (v2025.03.14) |
| Oct 12, 2025 | 56.17% (0.56167) | 97.97th | v4 (v2025.03.14) |
| Sep 28, 2025 | 63.83% (0.63828) | 98.38th | v4 (v2025.03.14) |
| Sep 18, 2025 | 56.17% (0.56167) | 98.04th | v4 (v2025.03.14) |
| Jul 13, 2025 | 59.87% (0.59873) | 98.14th | v4 (v2025.03.14) |
| Jul 10, 2025 | 67.08% (0.67080) | 98.45th | v4 (v2025.03.14) |
| Jun 2, 2025 | 68.61% (0.68606) | 98.52th | v4 (v2025.03.14) |
| May 15, 2025 | 67.08% (0.67080) | 98.43th | v4 (v2025.03.14) |
| Mar 30, 2025 | 56.96% (0.56958) | 97.94th | v4 (v2025.03.14) |
| Mar 29, 2025 | 76.20% (0.76196) | 98.60th | v4 (v2025.03.14) |
| Mar 28, 2025 | 56.96% (0.56958) | 97.94th | v4 (v2025.03.14) |
| Mar 27, 2025 | 76.20% (0.76196) | 98.83th | v4 (v2025.03.14) |
| Mar 20, 2025 | 56.96% (0.56958) | 97.97th | v4 (v2025.03.14) |
| Mar 19, 2025 | 75.74% (0.75740) | 98.83th | v4 (v2025.03.14) |
| Mar 17, 2025 | 56.96% (0.56958) | 97.91th | v4 (v2025.03.14) |
| Jan 13, 2025 | 7.75% (0.07749) | 94.20th | v3 (v2023.03.01) |
| Dec 17, 2024 | 9.62% (0.09618) | 94.78th | v3 (v2023.03.01) |
| Sep 10, 2024 | 13.00% (0.13000) | 95.62th | v3 (v2023.03.01) |
| Nov 8, 2023 | 15.30% (0.15300) | 95.28th | v3 (v2023.03.01) |
| Jul 8, 2023 | 91.93% (0.91928) | 98.48th | v3 (v2023.03.01) |
| Jun 18, 2023 | 91.26% (0.91256) | 98.39th | v3 (v2023.03.01) |
| May 22, 2023 | 92.52% (0.92524) | 98.47th | v3 (v2023.03.01) |
| Apr 25, 2023 | 85.05% (0.85045) | 97.96th | v3 (v2023.03.01) |
| Apr 13, 2023 | 82.49% (0.82489) | 97.84th | v3 (v2023.03.01) |
| Mar 17, 2023 | 85.70% (0.85699) | 97.94th | v3 (v2023.03.01) |
| Mar 7, 2023 | 94.13% (0.94132) | 98.62th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.55% (0.01547) | 74.98th | v2 (v2022.01.01) |
| Jun 24, 2022 | 1.55% (0.01547) | 73.47th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.16% (0.03164) | 82.35th | v2 (v2022.01.01) |
| Feb 18, 2022 | 23.85% (0.23854) | 95.13th | v2 (v2022.01.01) |
| Feb 4, 2022 | 44.83% (0.44833) | 97.74th | v2 (v2022.01.01) |
| Feb 3, 2022 | 41.22% (0.41221) | 98.25th | v1 |
| Jan 6, 2022 | 41.22% (0.41221) | 98.23th | v1 |
| Oct 21, 2021 | 13.52% (0.13517) | 96.08th | v1 |
| Sep 22, 2021 | 13.00% (0.13002) | 95.98th | v1 |
| Sep 1, 2021 | 4.73% (0.04733) | 87.00th | v1 |
| Jul 21, 2021 | 4.73% (0.04733) | 0.00th | v1 |
| Jun 15, 2021 | 4.53% (0.04526) | 0.00th | v1 |
| May 14, 2021 | 4.32% (0.04318) | 0.00th | v1 |
| Apr 14, 2021 | 4.11% (0.04110) | 0.00th | v1 |
References (45)
- https://access.redhat.com/security/cve/CVE-2020-5421 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1881158 Issue Tracking
- https://github.com/advisories/GHSA-rv39-3qh7-9v7w Advisory
- https://lists.apache.org/thread.html/r1c679c43fa4f7846d748a937955c7921436d1b315445978254442163%40%3Ccommits.ambari.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r1c679c43fa4f7846d748a937955c7921436d1b315445978254442163@%3Ccommits.ambari.apache.org%3E
- https://lists.apache.org/thread.html/r1eccdbd7986618a7319ee7a533bd9d9bf6e8678e59dd4cca9b5b2d7a%40%3Cissues.ambari.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r1eccdbd7986618a7319ee7a533bd9d9bf6e8678e59dd4cca9b5b2d7a@%3Cissues.ambari.apache.org%3E
- https://lists.apache.org/thread.html/r3589ed0d18edeb79028615080d5a0e8878856436bb91774a3196d9eb%40%3Ccommits.pulsar.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r3589ed0d18edeb79028615080d5a0e8878856436bb91774a3196d9eb@%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/r503e64b43a57fd68229cac4a869d1a9a2eac9e75f8719cad3a840211%40%3Ccommits.pulsar.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r503e64b43a57fd68229cac4a869d1a9a2eac9e75f8719cad3a840211@%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/r5c95eff679dfc642e9e4ab5ac6d202248a59cb1e9457cfbe8b729ac5%40%3Cissues.ambari.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r5c95eff679dfc642e9e4ab5ac6d202248a59cb1e9457cfbe8b729ac5@%3Cissues.ambari.apache.org%3E
- https://lists.apache.org/thread.html/r7e6a213eea7f04fc6d9e3bd6eb8d68c4df92a22e956e95cb2c482865%40%3Cissues.hive.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r7e6a213eea7f04fc6d9e3bd6eb8d68c4df92a22e956e95cb2c482865@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/r8b496b1743d128e6861ee0ed3c3c48cc56c505b38f84fa5baf7ae33a%40%3Cdev.ambari.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r8b496b1743d128e6861ee0ed3c3c48cc56c505b38f84fa5baf7ae33a@%3Cdev.ambari.apache.org%3E
- https://lists.apache.org/thread.html/r918caad55dcc640a16753b00d8d6acb90b4e36de4b6156d0867246ec%40%3Ccommits.pulsar.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r918caad55dcc640a16753b00d8d6acb90b4e36de4b6156d0867246ec@%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/r9f13cccb214495e14648d2c9b8f2c6072fd5219e74502dd35ede81e1%40%3Cdev.ambari.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r9f13cccb214495e14648d2c9b8f2c6072fd5219e74502dd35ede81e1@%3Cdev.ambari.apache.org%3E
- https://lists.apache.org/thread.html/ra889d95141059c6cbe77dd80249bb488ae53b274b5f3abad09d9511d%40%3Cuser.ignite.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/ra889d95141059c6cbe77dd80249bb488ae53b274b5f3abad09d9511d@%3Cuser.ignite.apache.org%3E
- https://lists.apache.org/thread.html/raf7ca57033e537e4f9d7df7f192fa6968c1e49409b2348e08d807ccb%40%3Cuser.ignite.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/raf7ca57033e537e4f9d7df7f192fa6968c1e49409b2348e08d807ccb@%3Cuser.ignite.apache.org%3E
- https://lists.apache.org/thread.html/rb18ed999153ef0f0cb7af03efe0046c42c7242fd77fbd884a75ecfdc%40%3Ccommits.pulsar.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rb18ed999153ef0f0cb7af03efe0046c42c7242fd77fbd884a75ecfdc@%3Ccommits.pulsar.apache.org%3E
- https://lists.apache.org/thread.html/rc9efaf6db98bee19db1bc911d0fa442287dac5cb229d4aaa08b6a13d%40%3Cissues.hive.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rc9efaf6db98bee19db1bc911d0fa442287dac5cb229d4aaa08b6a13d@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/rd462a8b0dfab4c15e67c0672cd3c211ecd0e4f018f824082ed54f665%40%3Cissues.hive.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rd462a8b0dfab4c15e67c0672cd3c211ecd0e4f018f824082ed54f665@%3Cissues.hive.apache.org%3E
- https://lists.apache.org/thread.html/re014a49d77f038ba70e5e9934d400af6653e8c9ac110d32b1254127e%40%3Cdev.ranger.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/re014a49d77f038ba70e5e9934d400af6653e8c9ac110d32b1254127e@%3Cdev.ranger.apache.org%3E
- https://lists.apache.org/thread.html/rf00d8f4101a1c1ea4de6ea1e09ddf7472cfd306745c90d6da87ae074%40%3Cdev.hive.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/rf00d8f4101a1c1ea4de6ea1e09ddf7472cfd306745c90d6da87ae074@%3Cdev.hive.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2020-5421
- https://security.netapp.com/advisory/ntap-20210513-0009/ x_refsource_CONFIRMThird Party Advisory
- https://tanzu.vmware.com/security/cve-2020-5421 x_refsource_CONFIRMVendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2020-5421
- https://www.oracle.com//security-alerts/cpujul2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuApr2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuapr2022.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2021.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpujan2022.html x_refsource_MISCPatchThird Party Advisory
- https://www.oracle.com/security-alerts/cpuoct2021.html x_refsource_MISCNot ApplicableThird Party Advisory
Change history (0)
No recorded changes yet.