CVE-2025-4328
Last modified
CVE-2025-4328 is a medium-severity vulnerability rated 5.1/10 on the CVSS scale. A vulnerability was found in fp2952 spring-cloud-base up to 7f050dc6db9afab82c5ce1d41cd74ed255ec9bfa. It has been declared as problematic. EPSS estimates a 0.26% chance of exploitation in the next 30 days.
Description
A vulnerability was found in fp2952 spring-cloud-base up to 7f050dc6db9afab82c5ce1d41cd74ed255ec9bfa. It has been declared as problematic. Affected by this vulnerability is the function sendBack of the file /spring-cloud-base-master/auth-center/auth-center-provider/src/main/java/com/peng/auth/provider/config/web/MvcController.java of the component HTTP Header Handler. The manipulation of the argument Referer leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-4328?
How severe is CVE-2025-4328?
How do I fix CVE-2025-4328?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-43274A privacy issue was addressed by removing the vulnerable cod…4.4
- CVE-2025-43275A race condition was addressed with additional validation. T…9.8
- CVE-2025-43276A logic error was addressed with improved error handling. Th…5.3
- CVE-2025-43277The issue was addressed with improved memory handling. This …7.8
- CVE-2025-43278This issue was addressed with improved handling of symlinks.…5.5
- CVE-2025-43279A privacy issue was addressed with improved private data red…6.2
- CVE-2025-43280The issue was resolved by not loading remote images. This is…4.7
- CVE-2025-43281The issue was addressed with improved authentication. This i…7.8
- CVE-2025-43282A double free issue was addressed with improved memory manag…5.5
- CVE-2025-43283An out-of-bounds read was addressed with improved bounds che…3.3
- CVE-2025-43284An out-of-bounds read was addressed with improved bounds che…5.5
- CVE-2025-43285A permissions issue was addressed with additional restrictio…5.5
Are you affected by CVE-2025-4328?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
