Launch Week Day 1: Announcing Security Design Review
HIGH 8.1 Maven

Spring Web vulnerable to Open Redirect or Server Side Request Forgery

GHSA-ccgv-vj62-xf9h · CVE-2024-22243

Published · Modified

Description

Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect attack or to a SSRF attack if the URL is used after passing validation checks.

Ready to move

Start Securing

Free, no credit card | First findings in minutes