~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
Candidate: CVE-2014-1904
PublicDate: 2014-03-20
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-1904
 http://www.gopivotal.com/security/cve-2014-1904
 https://jira.springsource.org/browse/SPR-11426
 https://github.com/spring-projects/spring-framework/commit/741b4b229ae032bd17175b46f98673ce0bd2d485
 http://docs.spring.io/spring/docs/3.2.8.RELEASE/changelog.txt
Description:
 Cross-site scripting (XSS) vulnerability in
 web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0
 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject
 arbitrary web script or HTML via the requested URI in a default action.
Ubuntu-Description:
Notes:
Bugs:
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=741604
Priority: medium
Discovered-by:
Assigned-to:

Patches_libspring-java:
upstream_libspring-java: needs-triage
lucid_libspring-java: DNE
precise_libspring-java: ignored (reached end-of-life)
precise/esm_libspring-java: DNE (precise was needed)
quantal_libspring-java: ignored (reached end-of-life)
saucy_libspring-java: ignored (reached end-of-life)
trusty_libspring-java: needed
utopic_libspring-java: ignored (reached end-of-life)
vivid_libspring-java: ignored (reached end-of-life)
vivid/stable-phone-overlay_libspring-java: DNE
vivid/ubuntu-core_libspring-java: DNE
wily_libspring-java: ignored (reached end-of-life)
xenial_libspring-java: needed
yakkety_libspring-java: ignored (reached end-of-life)
zesty_libspring-java: needed
devel_libspring-java: needed