VRT 391,192 CVEs tracked · 15,442 in RASP scope · data as of 18 hours ago

CVE-2018-11040

7.5 High Mitigated by environment configuration

Description

Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not enabled by default in Spring Framework nor Spring Boot, however, when MappingJackson2JsonView is configured in an application, JSONP support is automatically ready to use through the "jsonp" and "callback" JSONP parameters, enabling cross-domain requests.

CWE-829

Exploitation Status

No public exploit

Nothing published shows this CVE being exploited, which is not the same as ruling it out. nothing published in 8 years.

CVSS E:U

  • CISA KEV not listed
  • CISA Vulnrichment no assessment published
  • Indexed PoC none indexed
  • EPSS 3.2% chance in 30 days

Waratek Defense Posture

Mitigated by environment configuration

The vulnerability is mitigated through deployment or application configuration rather than by an ARMR rule. This is a historical determination; the specific configuration change may not be recorded.

  • Protection full the deployment environment, not the agent
  • Action not-needed
  • Review human manual-review
  • Record active
Decided by manual classification : Manual classification of this CVE in the legacy dataset
Finding Manual classification assigned status: MITIGATED-BY-ENVIRONMENT

CVSS

7.5 HIGH v3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 2 metrics

VRT selects the newest version's highest entry and publishes it as cvssScore, newest rather than largest because scores are not comparable across versions, and highest rather than first because the first entry is frequently a CNA placeholder scoring 0.0 over NVD's own analysis.

VersionScoreBandVectorAssignerType
CVSS 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N NVD Primary published
CVSS 2.0 4.3 no band published AV:N/AC:M/Au:N/C:P/I:N/A:N NVD Primary

Affected Software & Releases

☕ Maven Library Packages

Artifact coordinates and fix boundaries from OSV.dev
Package CoordinateIntroducedFixedLast affected
org.springframework:spring-core 5.0.0.RELEASE 5.0.7.RELEASE unbounded
org.springframework:spring-core 4.3.0.RELEASE 4.3.18.RELEASE unbounded

🖥️ Product CPEs & Version Ranges

29 product(s) over 53 version claims (uncapped)
SourceVendorProductSchemeAffected Versions
nvd debian debian linux generic 9.0
nvd oracle agile product lifecycle management generic 9.3.3 · 9.3.4 · 9.3.5
nvd oracle application testing suite generic 12.5.0.3 · 13.1.0.1 · 13.2.0.1 · 13.3.0.1
nvd oracle communications network integrity generic ≥ 7.3.2 and ≤ 7.3.6
nvd oracle communications online mediation controller generic 6.1
nvd oracle communications services gatekeeper generic < 6.1.0.4.0
nvd oracle communications unified inventory management generic 7.3.2 · 7.3.4 · 7.3.5 · 7.4.0
nvd oracle endeca information discovery integrator generic 3.1.0 · 3.2.0
nvd oracle enterprise manager generic 13.2
nvd oracle enterprise manager ops center generic 12.3.3
nvd oracle flexcube private banking generic 2.0.0.0 · 2.2.0.1 · 12.0.1.0 · 12.0.3.0 · 12.1.0.0
nvd oracle healthcare master person index generic 3.0 · 4.0
nvd oracle hospitality guest access generic 4.2.0 · 4.2.1
nvd oracle insurance calculation engine generic ≥ 11.0.0 and ≤ 11.3.1
nvd oracle insurance rules palette generic 10.0 · 10.2
nvd oracle micros lucas generic 2.9.5
nvd oracle mysql enterprise monitor generic ≤ 3.4.9.4237 · ≥ 3.4.10 and ≤ 4.0.6.5281 · ≥ 4.0.7 and ≤ 8.0.2.8191
nvd oracle product lifecycle management generic 9.3.6
nvd oracle retail advanced inventory planning generic 15.0
nvd oracle retail clearance optimization engine generic 14.0.5
nvd oracle retail customer insights generic 15.0 · 16.0
nvd oracle retail markdown optimization generic 13.4.4
nvd oracle retail predictive application server generic 14.0.3.26 · 14.1.3.37 · 15.0.3.100 · 16.0
nvd oracle retail service backbone generic 16.0.1
nvd oracle retail xstore point of service generic 7.1
nvd oracle utilities network management system generic 1.12.0.3
nvd oracle weblogic server generic 12.2.1.3.0
osv org.springframework spring-core generic ≥ 4.3.0 and < 4.3.18 · ≥ 5.0.0 and < 5.0.7
nvd vmware spring framework generic < 4.3.18 · ≥ 5.0.0 and < 5.0.7

References

URLTags
https://github.com/spring-projects/spring-framework/commit/874859493bbda59739c38c7e52eb3625f247b93a WEB
https://github.com/spring-projects/spring-framework/commit/b80c13b722bb207ddf43f53a007ee3ddc1dd2e26 WEB
https://github.com/advisories/GHSA-f26x-pr96-vw86 ADVISORY
https://github.com/spring-projects/spring-framework PACKAGE
https://lists.debian.org/debian-lts-announce/2021/04/msg00022.html WEB
https://pivotal.io/security/cve-2018-11040 WEB
https://www.oracle.com/security-alerts/cpujan2020.html WEB
https://www.oracle.com/security-alerts/cpujul2020.html WEB
https://www.oracle.com/security-alerts/cpuoct2021.html WEB
https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html WEB

Timeline

Published 2018-06-25 Last modified 2026-06-17
Published2018-06-25By the CVE Program.
NVD record modified2026-06-17NVD's own last-modified date for this record.