Metrics
Affected Vendors & Products
Tue, 06 May 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 06 May 2025 07:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability was found in fp2952 spring-cloud-base up to 7f050dc6db9afab82c5ce1d41cd74ed255ec9bfa. It has been declared as problematic. Affected by this vulnerability is the function sendBack of the file /spring-cloud-base-master/auth-center/auth-center-provider/src/main/java/com/peng/auth/provider/config/web/MvcController.java of the component HTTP Header Handler. The manipulation of the argument Referer leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. | |
Title | fp2952 spring-cloud-base HTTP Header MvcController.java sendBack redirect | |
Weaknesses | CWE-601 | |
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-05-06T07:00:07.092Z
Updated: 2025-05-06T14:14:12.642Z
Reserved: 2025-05-05T14:57:25.516Z
Link: CVE-2025-4328

Updated: 2025-05-06T14:14:06.115Z

Status : Awaiting Analysis
Published: 2025-05-06T07:15:48.823
Modified: 2025-05-07T14:13:35.980
Link: CVE-2025-4328

No data.