CVE-2018-11040Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not enabled by default in Spring Framework nor Spring Boot, however, when MappingJackson2JsonView is configured in an application, JSONP support is automatically ready to use through the "jsonp" and "callback" JSONP parameters, enabling cross-domain requests.
CWE-829
No public exploit
Nothing published shows this CVE being exploited, which is not the same as ruling it out. nothing published in 8 years.
CVSS E:U
Mitigated by environment configuration
The vulnerability is mitigated through deployment or application configuration rather than by an ARMR rule. This is a historical determination; the specific configuration change may not be recorded.
| Decided by | manual classification : Manual classification of this CVE in the legacy dataset |
|---|---|
| Finding | Manual classification assigned status: MITIGATED-BY-ENVIRONMENT |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
2 metrics
VRT selects the newest version's highest entry and
publishes it as cvssScore, newest rather than largest because scores are not comparable
across versions, and highest rather than first because the first entry is frequently a CNA placeholder
scoring 0.0 over NVD's own analysis.
| Version | Score | Band | Vector | Assigner | Type | |
|---|---|---|---|---|---|---|
| CVSS 3.1 | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
NVD | Primary | published |
| CVSS 2.0 | 4.3 | no band published | AV:N/AC:M/Au:N/C:P/I:N/A:N |
NVD | Primary |
| Package Coordinate | Introduced | Fixed | Last affected |
|---|---|---|---|
org.springframework:spring-core |
5.0.0.RELEASE | 5.0.7.RELEASE |
unbounded |
org.springframework:spring-core |
4.3.0.RELEASE | 4.3.18.RELEASE |
unbounded |
| Source | Vendor | Product | Scheme | Affected Versions |
|---|---|---|---|---|
| nvd | debian | debian linux | generic | 9.0 |
| nvd | oracle | agile product lifecycle management | generic | 9.3.3 · 9.3.4 · 9.3.5 |
| nvd | oracle | application testing suite | generic | 12.5.0.3 · 13.1.0.1 · 13.2.0.1 · 13.3.0.1 |
| nvd | oracle | communications network integrity | generic | ≥ 7.3.2 and ≤ 7.3.6 |
| nvd | oracle | communications online mediation controller | generic | 6.1 |
| nvd | oracle | communications services gatekeeper | generic | < 6.1.0.4.0 |
| nvd | oracle | communications unified inventory management | generic | 7.3.2 · 7.3.4 · 7.3.5 · 7.4.0 |
| nvd | oracle | endeca information discovery integrator | generic | 3.1.0 · 3.2.0 |
| nvd | oracle | enterprise manager | generic | 13.2 |
| nvd | oracle | enterprise manager ops center | generic | 12.3.3 |
| nvd | oracle | flexcube private banking | generic | 2.0.0.0 · 2.2.0.1 · 12.0.1.0 · 12.0.3.0 · 12.1.0.0 |
| nvd | oracle | healthcare master person index | generic | 3.0 · 4.0 |
| nvd | oracle | hospitality guest access | generic | 4.2.0 · 4.2.1 |
| nvd | oracle | insurance calculation engine | generic | ≥ 11.0.0 and ≤ 11.3.1 |
| nvd | oracle | insurance rules palette | generic | 10.0 · 10.2 |
| nvd | oracle | micros lucas | generic | 2.9.5 |
| nvd | oracle | mysql enterprise monitor | generic | ≤ 3.4.9.4237 · ≥ 3.4.10 and ≤ 4.0.6.5281 · ≥ 4.0.7 and ≤ 8.0.2.8191 |
| nvd | oracle | product lifecycle management | generic | 9.3.6 |
| nvd | oracle | retail advanced inventory planning | generic | 15.0 |
| nvd | oracle | retail clearance optimization engine | generic | 14.0.5 |
| nvd | oracle | retail customer insights | generic | 15.0 · 16.0 |
| nvd | oracle | retail markdown optimization | generic | 13.4.4 |
| nvd | oracle | retail predictive application server | generic | 14.0.3.26 · 14.1.3.37 · 15.0.3.100 · 16.0 |
| nvd | oracle | retail service backbone | generic | 16.0.1 |
| nvd | oracle | retail xstore point of service | generic | 7.1 |
| nvd | oracle | utilities network management system | generic | 1.12.0.3 |
| nvd | oracle | weblogic server | generic | 12.2.1.3.0 |
| osv | org.springframework | spring-core | generic | ≥ 4.3.0 and < 4.3.18 · ≥ 5.0.0 and < 5.0.7 |
| nvd | vmware | spring framework | generic | < 4.3.18 · ≥ 5.0.0 and < 5.0.7 |
| Published | 2018-06-25 | By the CVE Program. |
|---|---|---|
| NVD record modified | 2026-06-17 | NVD's own last-modified date for this record. |