CVE-2018-1229
Last modified
CVE-2018-1229 is a vulnerability of currently unknown severity. Pivotal Spring Batch Admin, all versions, contains a stored XSS vulnerability in the file upload feature. An unauthenticated malicious user with network access to Spring Batch Admin could store an arbitrary web script that would be executed by other users. EPSS estimates a 0.75% chance of exploitation in the next 30 days.
Description
Pivotal Spring Batch Admin, all versions, contains a stored XSS vulnerability in the file upload feature. An unauthenticated malicious user with network access to Spring Batch Admin could store an arbitrary web script that would be executed by other users. This issue has not been patched because Spring Batch Admin has reached end of life.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pivotal Software | Spring Batch Admin | All versions |
References
- http://www.securityfocus.com/bid/103462Third Party Advisory, VDB Entry
- https://pivotal.io/security/cve-2018-1229Vendor Advisory
- http://www.securityfocus.com/bid/103462Third Party Advisory, VDB Entry
- https://pivotal.io/security/cve-2018-1229Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-1229?
How severe is CVE-2018-1229?
How do I fix CVE-2018-1229?
Are you affected by CVE-2018-1229?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
