Junglewise Threat Intelligence

CVE-2020-5397: CSRF attack via CORS preflight requests with Spring MVC or Spring WebFlux

CVE-2020-5397 · Severity: low · CVSS 3 · Published 2020-01-21

Technologies: org.springframework:spring-webmvc (Maven). Vendors: Maven.

Executive brief

CSRF attack via CORS preflight requests with Spring MVC or Spring WebFlux

Affected products

  • Maven org.springframework:spring-webflux
  • Maven org.springframework:spring-webmvc

Related threats