CVE-2018-11040 describes a vulnerability in Spring Framework versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18, and older unsupported versions, that allows cross-domain requests via JSONP when MappingJackson2JsonView is configured. This vulnerability, affecting products like Debian, Oracle, and VMware, carries a high CVSS score of 7.5, indicating a network-exploitable issue with high confidentiality impact. While the vulnerability is not actively exploited and no public exploit code or Metasploit modules exist, its presence allows for unauthorized data access if JSONP is enabled. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.3.18CPE matchmatch criteria | cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:* | ||
>= 5.0.0, < 5.0.7CPE matchmatch criteria | cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:* | ||
9.3.3CPE matchmatch criteria | cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.3:*:*:*:*:*:*:* | ||
9.3.4CPE matchmatch criteria | cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.4:*:*:*:*:*:*:* | ||
9.3.5CPE matchmatch criteria | cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.