CVE-2018-11039
Executive Summary
CVE-2018-11039 exposes Spring Framework (5.0.x <5.0.7, 4.3.x <4.3.18, and older unsupported releases) to a method‑override flaw via HiddenHttpMethodFilter. The filter allows any HTTP method—including TRACE—to be set on a request. If an application already has an XSS vulnerability, an attacker can combine the two to perform a Cross‑Site Tracing (XST) attack, leaking sensitive data or session information. The vulnerability is not listed in CISA KEV.
Authoritative CVE Metadata - CVSS Base Score: 5.9 (MEDIUM) - Published: 2018-06-25T15:29:00.317 - Last Modified: 2026-08-25T16:28:27.310
Original Description: Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.
"One that desires to excel should endeavour in those things that are in themselves most excellent."
— Epictetus