CVE-2011-2730

VMware SpringSource Spring Framework before 2.5.6.SEC03, 2.5.7.SR023, and 3.x before 3.0.6, when a container supports Expression Language (EL), evaluates EL expressions in tags twice, which allows remote attackers to obtain sensitive information via a (1) name attribute in a (a) spring:hasBindErrors tag; (2) path attribute in a (b) spring:bind or (c) spring:nestedpath tag; (3) arguments, (4) code, (5) text, (6) var, (7) scope, or (8) message attribute in a (d) spring:message or (e) spring:theme tag; or (9) var, (10) scope, or (11) value attribute in a (f) spring:transform tag, aka "Expression Language Injection."
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
VendorProductVersion
springsourcespring_framework
𝑥
≤ 2.5.7_sr01
springsourcespring_framework
𝑥
≤ 3.0.5
springsourcespring_framework
2.5.0
springsourcespring_framework
2.5.0:rc1
springsourcespring_framework
2.5.0:rc2
springsourcespring_framework
2.5.1
springsourcespring_framework
2.5.2
springsourcespring_framework
2.5.3
springsourcespring_framework
2.5.4
springsourcespring_framework
2.5.5
springsourcespring_framework
2.5.6
springsourcespring_framework
2.5.7
springsourcespring_framework
3.0.0
springsourcespring_framework
3.0.1
springsourcespring_framework
3.0.2
springsourcespring_framework
3.0.3
springsourcespring_framework
3.0.4
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libspring-2.5-java
saucy
dne
raring
dne
quantal
dne
precise
dne
oneiric
ignored
natty
ignored
lucid
ignored
hardy
dne
Common Weakness Enumeration
References