RFD Protection Bypass via jsessionid

HIGH | SEPTEMBER 17, 2020 | CVE-2020-5421

Description

In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.

Affected Spring Products and Versions

Spring Framework:

  • 5.2.0.RELEASE - 5.2.8.RELEASE
  • 5.1.0.RELEASE - 5.1.17.RELEASE
  • 5.0.0.RELEASE - 5.0.18.RELEASE
  • 4.3.28.RELEASE and earlier

Mitigation

Users of affected versions should upgrade to the corresponding fixed version.
Fix versionAvailability
5.2.9.RELEASEOSS
5.1.18.RELEASEOSS
5.0.19.RELEASEOSS
4.3.29.RELEASEOSS

No further mitigation steps are necessary.

Credit

This issue was identified and responsibly reported by Keitaro Yamazaki / Ierae Security.

History

  • 2020-09-17: Initial vulnerability report published.

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all