This is the same as CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-hgjh-9rj2-g67j | Spring Framework URL Parsing with Host Validation Vulnerability |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 10 Jun 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Netapp
Netapp active Iq Unified Manager Vmware Vmware spring Framework |
|
| CPEs | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:* cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Netapp
Netapp active Iq Unified Manager Vmware Vmware spring Framework |
Thu, 13 Feb 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing validation checks. This is the same as CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input. | Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing validation checks. This is the same as CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input. |
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2025-02-13T17:33:39.598Z
Reserved: 2024-01-08T18:43:15.943Z
Link: CVE-2024-22259
Updated: 2024-08-01T22:43:34.152Z
Status : Analyzed
Published: 2024-03-16T05:15:20.830
Modified: 2025-06-10T15:55:48.787
Link: CVE-2024-22259
OpenCVE Enrichment
No data.
Github GHSA