VYPR
High severity8.8NVD Advisory· Published Mar 21, 2018· Updated Jun 17, 2026

CVE-2018-1230

CVE-2018-1230

Description

Pivotal Spring Batch Admin, all versions, does not contain cross site request forgery protection. A remote unauthenticated user could craft a malicious site that executes requests to Spring Batch Admin. This issue has not been patched because Spring Batch Admin has reached end of life.

Affected products

3
  • cpe:2.3:a:pivotal_software:spring_batch_admin:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:pivotal_software:spring_batch_admin:*:*:*:*:*:*:*:*
    • (no CPE)range: all versions
  • Spring by Pivotal/Spring Batch Adminv5
    Range: All

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.