CVE
GHSA-w5r6-gx3q-hmxj
springframework-social Cross-Site Request Forgery vulnerability
Cross-site request forgery (CSRF) vulnerability in springframework-social before 1.1.3.
Package Versions Affected
Package Version
patch Availability
Automatically patch vulnerabilities without upgrading
Fix Without Upgrading
Detect compatible fix
Apply safe remediation
Fix with a single pull request
CVSS Version
Severity
Base Score
CVSS Version
Score Vector

C
H
U
8.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

C
H
U
0
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

C
H
U
8.8
-
3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Related Resources
No items found.
References
https://nvd.nist.gov/vuln/detail/CVE-2015-5258, https://bugzilla.redhat.com/show_bug.cgi?id=1305443, https://github.com/spring-projects/spring-social, http://lists.fedoraproject.org/pipermail/package-announce/2016-February/177420.html
