« Volver al listado

CVE-2024-22243

Estado: AplazadaAlta (8.1)—

Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-22243",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-22243",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-06-27T00:00:00+00:00"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@vmware.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "Spring",
          "product": "Spring Framework",
          "versions": [
            {
              "status": "affected",
              "version": "6.0.x",
              "lessThan": "6.0.17",
              "versionType": "6.0.17"
            },
            {
              "status": "affected",
              "version": "6.1.x",
              "lessThan": "6.1.4",
              "versionType": "6.1.4"
            },
            {
              "status": "affected",
              "version": "5.3.x",
              "lessThan": "5.3.32",
              "versionType": "5.3.32"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:vmware:spring_framework:6.0.0:-:*:*:*:*:*:*"
          ],
          "vendor": "vmware",
          "product": "spring_framework",
          "versions": [
            {
              "status": "affected",
              "version": "6.0.0",
              "lessThan": "6.0.17",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:vmware:spring_framework:6.1.0:*:*:*:*:*:*:*"
          ],
          "vendor": "vmware",
          "product": "spring_framework",
          "versions": [
            {
              "status": "affected",
              "version": "6.1.0",
              "lessThan": "6.1.4",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:pivotal_software:spring_framework:5.3.0:*:*:*:*:*:*:*"
          ],
          "vendor": "pivotal_software",
          "product": "spring_framework",
          "versions": [
            {
              "status": "affected",
              "version": "5.3.0",
              "lessThan": "5.3.32",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*"
          ],
          "vendor": "netapp",
          "product": "active_iq_unified_manager",
          "versions": [
            {
              "status": "affected",
              "version": "5.0"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*"
          ],
          "vendor": "netapp",
          "product": "active_iq_unified_manager",
          "versions": [
            {
              "status": "affected",
              "version": "5.0"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*"
          ],
          "vendor": "netapp",
          "product": "active_iq_unified_manager",
          "versions": [
            {
              "status": "affected",
              "version": "5.0"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-02-23T05:15:08.143",
  "references": [
    {
      "url": "https://security.netapp.com/advisory/ntap-20240524-0001/",
      "source": "security@vmware.com"
    },
    {
      "url": "https://spring.io/security/cve-2024-22243",
      "source": "security@vmware.com"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2024/Sep/24",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20240524-0001/",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://spring.io/security/cve-2024-22243",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-601"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a  open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks."
    },
    {
      "lang": "es",
      "value": "Las aplicaciones que utilizan UriComponentsBuilder para analizar una URL proporcionada externamente (por ejemplo, a través de un parámetro de consulta) Y realizan comprobaciones de validación en el host de la URL analizada pueden ser vulnerables a una redirección abierta https://cwe.mitre.org/data/definitions/601 .html o a un ataque SSRF si la URL se utiliza después de pasar las comprobaciones de validación."
    }
  ],
  "lastModified": "2026-06-17T07:11:01.040",
  "sourceIdentifier": "security@vmware.com"
}