CVE-2018-1230: Spring Batch Admin vulnerable to Cross Site Request Forgery
Severity
Medium
Vendor
Spring by Pivotal
Description
Spring Batch Admin does not contain Cross Site Request Forgery (CSRF) protection, which may allow an attacker to craft a malicious site that executes requests to Spring Batch Admin.
Affected Pivotal Products and Versions
Severity is medium unless otherwise noted.
- Spring Batch Admin all versions
Mitigation
Users of affected versions should apply the following mitigation:
- Spring Batch Admin has reached end of life as of January 1, 2018. Spring Cloud Data Flow is the recommended replacement for managing and monitoring Spring Batch jobs going forward.
Credit
This vulnerability was responsibly reported by Wen Bin Kong.
References
- https://docs.spring.io/spring-batch-admin
- https://github.com/spring-projects/spring-batch-admin/blob/master/MIGRATION.md
History
2018-03-16: Initial vulnerability report published.