CVE-2020-5397: CSRF Attack via CORS Preflight Requests with Spring MVC or Spring WebFlux

Published Jan 17, 2020
·
Updated

Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail authentication. However a notable exception to this are Chrome based browsers when using client certificates for authentication since Chrome sends TLS client certificates in CORS preflight requests in violation of spec requirements. No HTTP body can be sent or received as a result of this attack.

Affected Software

54 affected componentsFixes available
maven/org.springframework:spring-webflux>=5.2.0<5.2.3
5.2.3
maven/org.springframework:spring-webmvc>=5.2.0<5.2.3
5.2.3
VMware Spring Framework>=5.2.0<5.2.3
Oracle Application Testing Suite=13.3.0.1
Oracle Communications Brm - Elastic Charging Engine=11.3
Oracle Communications Brm - Elastic Charging Engine=12.0
Oracle Communications Diameter Signaling Router>=8.0.0<=8.2.2
Oracle Communications Element Manager=8.1.1
Oracle Communications Element Manager=8.2.0
Oracle Communications Element Manager=8.2.1
Oracle Communications Policy Management=12.5.0
Oracle Communications Session Route Manager=8.1.1
Oracle Communications Session Route Manager=8.2.0
Oracle Communications Session Route Manager=8.2.1
Oracle Enterprise Manager Base Platform=13.2.1.0
Oracle Financial Services Regulatory Reporting With Agilereporter=8.0.9.2.0
Oracle FLEXCUBE Private Banking=12.0.0
Oracle FLEXCUBE Private Banking=12.1.0
Oracle Healthcare Master Person Index=4.0.2
Oracle Insurance Calculation Engine>=11.0.0<=11.3.1
Oracle Insurance Policy Administration J2EE=10.2.0
Oracle Insurance Policy Administration J2EE=10.2.4
Oracle Insurance Policy Administration J2EE=11.0.2
Oracle Insurance Policy Administration J2EE=11.1.0
Oracle Insurance Policy Administration J2EE=11.2.0
Oracle Insurance Rules Palette=10.2.0
Oracle Insurance Rules Palette=10.2.4
Oracle Insurance Rules Palette=11.0.2
Oracle Insurance Rules Palette=11.1.0
Oracle Insurance Rules Palette=11.2.0
Oracle MySQL Enterprise Monitor>=4.0.0<=4.0.12
Oracle MySQL Enterprise Monitor>=8.0.0<=8.0.20
Oracle Rapid Planning=12.1
Oracle Rapid Planning=12.2
Oracle Retail Assortment Planning=15.0
Oracle Retail Assortment Planning=16.0
Oracle Retail Back Office=14.1
Oracle Retail Central Office=14.1
Oracle Retail Financial Integration=15.0
Oracle Retail Financial Integration=16.0
Oracle Retail Integration Bus=15.0.3
Oracle Retail Integration Bus=16.0.3
Oracle Retail Order Broker=15.0
Oracle Retail Order Broker=16.0
Oracle Retail Point-of-Service=14.1
Oracle Retail Predictive Application Server=14.0.3
Oracle Retail Predictive Application Server=14.1.3
Oracle Retail Predictive Application Server=15.0.3.0
Oracle Retail Predictive Application Server=16.0.3.0
Oracle Retail Returns Management=14.1
Oracle Retail Service Backbone=15.0
Oracle Retail Service Backbone=16.0
Oracle WebLogic Server=12.2.1.3.0
Oracle WebLogic Server=12.2.1.4.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade maven/org.springframework:spring-webflux to a version that resolves this vulnerability.

    Fixed in 5.2.3
  2. Upgrade

    Upgrade maven/org.springframework:spring-webmvc to a version that resolves this vulnerability.

    Fixed in 5.2.3
  3. Upgrade

    Upgrade Spring Framework (spring-webmvc / spring-webflux) to a version that resolves this vulnerability.

    Fixed in 5.2.3

Event History

Jan 17, 2020
CVE Published
via MITRE·06:50 PM
Data Sourced
via MITRE·06:50 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jan 21, 2020
Advisory Published
via GitHub·08:59 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2020-5397?

The severity of CVE-2020-5397 is medium with a severity value of 5.3.

2

Which software versions are affected by CVE-2020-5397?

Spring Framework versions 5.2.x prior to 5.2.3, VMware Spring Framework, and Oracle Application Testing Suite are affected by CVE-2020-5397.

3

How does CVE-2020-5397 impact Spring Framework?

CVE-2020-5397 allows CSRF attacks through CORS preflight requests targeting Spring MVC or Spring WebFlux endpoints.

4

What are the reference links for CVE-2020-5397?

The reference links for CVE-2020-5397 are: [Link 1](https://pivotal.io/security/cve-2020-5397), [Link 2](https://www.oracle.com//security-alerts/cpujul2021.html), [Link 3](https://www.oracle.com/security-alerts/cpuapr2020.html).

5

What is the Common Weakness Enumeration (CWE) for CVE-2020-5397?

The Common Weakness Enumeration (CWE) for CVE-2020-5397 is CWE-352.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203