Vulnerability Change Records for CVE-2020-5398

Change History

CVE Modified by Pivotal Software, Inc. 5/14/2020 6:15:12 AM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r0f3530f7cb510036e497532ffc4e0bd0b882940448cf4e233994b08b@%3Ccommits.karaf.apache.org%3E [No Types Assigned]
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r7361bfe84bde9d233f9800c3a96673e7bd81207549ced0236f07a29d@%3Cissues.karaf.apache.org%3E [No Types Assigned]
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r8736185eb921022225a83e56d7285a217fd83f5524bd64a6ca3bf5cc@%3Cissues.karaf.apache.org%3E [No Types Assigned]
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r9fb1ee08cf337d16c3364feb0f35a072438c1a956afd7b77859aa090@%3Cissues.karaf.apache.org%3E [No Types Assigned]

CVE Modified by Pivotal Software, Inc. 6/14/2021 2:15:32 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://www.oracle.com/security-alerts/cpuApr2021.html [No Types Assigned]

CVE Modified by Pivotal Software, Inc. 4/10/2020 5:15:12 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/rdcaadaa9a68b31b7d093d76eacfaacf6c7a819f976b595c75ad2d4dc@%3Cdev.geode.apache.org%3E [No Types Assigned]

CVE Modified by Pivotal Software, Inc. 5/18/2020 6:15:11 AM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r0f2d0ae1bad2edb3d4a863d77f3097b5e88cfbdae7b809f4f42d6aad@%3Cissues.karaf.apache.org%3E [No Types Assigned]
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r4639e821ef9ca6ca10887988f410a60261400a7766560e7a97a22efc@%3Ccommits.karaf.apache.org%3E [No Types Assigned]
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r6dac0e365d1b2df9a7ffca12b4195181ec14ff0abdf59e1fdb088ce5@%3Ccommits.karaf.apache.org%3E [No Types Assigned]
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/rb4d1fc078f086ec2e98b2693e8b358e58a6a4ef903ceed93a1ee2b18@%3Ccommits.karaf.apache.org%3E [No Types Assigned]

CVE Modified by Pivotal Software, Inc. 10/20/2020 6:15:44 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://www.oracle.com/security-alerts/cpuoct2020.html [No Types Assigned]

Reanalysis 1/27/2020 12:37:19 PM

Action Type Old Value New Value
Changed CPE Configuration
OR
     *cpe:2.3:a:pivotal_software:spring_framework:*:*:*:*:*:*:*:* versions from (including) 5.2.0 up to (excluding) 5.2.3
     *cpe:2.3:a:pivotal_software:spring_security:*:*:*:*:*:*:*:* versions from (including) 5.0.0 up to (excluding) 5.0.16
     *cpe:2.3:a:pivotal_software:spring_security:*:*:*:*:*:*:*:* versions from (including) 5.1.0 up to (excluding) 5.1.13
OR
     *cpe:2.3:a:pivotal_software:spring_framework:*:*:*:*:*:*:*:* versions from (including) 5.0.0 up to (excluding) 5.0.16
     *cpe:2.3:a:pivotal_software:spring_framework:5.1.0:-:*:*:*:*:*:*
     *cpe:2.3:a:pivotal_software:spring_framework:5.1.0:rc1:*:*:*:*:*:*
     *cpe:2.3:a:pivotal_software:spring_framework:5.1.0:rc2:*:*:*:*:*:*
     *cpe:2.3:a:pivotal_software:spring_framework:5.1.0:rc3:*:*:*:*:*:*
     *cpe:2.3:a:pivotal_software:spring_framework:*:*:*:*:*:*:*:* versions from (including) 5.1.1 up to (excluding) 5.1.13
     *cpe:2.3:a:pivotal_software:spring_framework:*:*:*:*:*:*:*:* versions from (including) 5.2.0 up to (excluding) 5.2.3

CVE Modified by Pivotal Software, Inc. 10/21/2020 2:15:13 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r5c95eff679dfc642e9e4ab5ac6d202248a59cb1e9457cfbe8b729ac5@%3Cissues.ambari.apache.org%3E [No Types Assigned]

CVE Modified by Pivotal Software, Inc. 5/27/2020 5:15:10 AM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r712a6fce928e24e7b6ec30994a7e115a70f1f6e4cf2c2fbf0347ce46@%3Ccommits.servicecomb.apache.org%3E [No Types Assigned]

CVE Modified by Pivotal Software, Inc. 5/17/2020 2:15:11 AM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r028977b9b9d44a89823639aa3296fb0f0cfdd76b4450df89d3c4fbbf@%3Cissues.karaf.apache.org%3E [No Types Assigned]
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r1bc5d673c01cfbb8e4a91914e9748ead3e5f56b61bca54d314c0419b@%3Cissues.karaf.apache.org%3E [No Types Assigned]
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r4b1886e82cc98ef38f582fef7d4ea722e3fcf46637cd4674926ba682@%3Cissues.karaf.apache.org%3E [No Types Assigned]
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r74f81f93a9b69140fe41e236afa7cbe8dfa75692e7ab31a468fddaa0@%3Ccommits.karaf.apache.org%3E [No Types Assigned]
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/rab0de39839b4c208dcd73f01e12899dc453361935a816a784548e048@%3Cissues.karaf.apache.org%3E [No Types Assigned]
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/reaa8a6674baf2724b1b88a621b0d72d9f7a6f5577c88759842c16eb6@%3Ccommits.karaf.apache.org%3E [No Types Assigned]

CVE Modified by Pivotal Software, Inc. 3/17/2021 11:15:11 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r27552d2fa10d96f2810c50d16ad1fd1899e37796c81a0c5e7585a02d@%3Cdev.rocketmq.apache.org%3E [No Types Assigned]
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r645408661a8df9158f49e337072df39838fa76da629a7e25a20928a6@%3Cdev.rocketmq.apache.org%3E [No Types Assigned]
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/rc9c7f96f08c8554225dba9050ea5e64bebc129d0d836303143fe3160@%3Cdev.rocketmq.apache.org%3E [No Types Assigned]

CVE Modified by Pivotal Software, Inc. 9/17/2021 6:15:07 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://security.netapp.com/advisory/ntap-20210917-0006/ [No Types Assigned]

CVE Modified by Pivotal Software, Inc. 10/13/2020 4:15:12 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r1eccdbd7986618a7319ee7a533bd9d9bf6e8678e59dd4cca9b5b2d7a@%3Cissues.ambari.apache.org%3E [No Types Assigned]

CVE Modified by Pivotal Software, Inc. 4/15/2020 5:15:36 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://www.oracle.com/security-alerts/cpuapr2020.html [No Types Assigned]

CVE Modified by Pivotal Software, Inc. 1/20/2021 10:15:42 AM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://www.oracle.com/security-alerts/cpujan2021.html [No Types Assigned]

CVE Modified by Pivotal Software, Inc. 7/14/2020 11:15:52 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://www.oracle.com/security-alerts/cpujul2020.html [No Types Assigned]

CVE Modified by Pivotal Software, Inc. 6/18/2020 11:15:10 AM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r881fb5a95ab251106fed38f836257276feb026bfe01290e72ff91c2a@%3Ccommits.servicecomb.apache.org%3E [No Types Assigned]
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/ra996b56e1f5ab2fed235a8b91fa0cc3cf34c2e9fee290b7fa4380a0d@%3Ccommits.servicecomb.apache.org%3E [No Types Assigned]

CVE Modified by Pivotal Software, Inc. 5/18/2020 3:15:12 AM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r1accbd4f31ad2f40e1661d70a4510a584eb3efd1e32e8660ccf46676@%3Ccommits.karaf.apache.org%3E [No Types Assigned]
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r2dfd5b331b46d3f90c4dd63a060e9f04300468293874bd7e41af7163@%3Cissues.karaf.apache.org%3E [No Types Assigned]
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r8cc37a60a5056351377ee5f1258f2a4fdd39822a257838ba6bcc1e88@%3Ccommits.karaf.apache.org%3E [No Types Assigned]

CVE Modified by Pivotal Software, Inc. 5/14/2020 7:15:11 AM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r3765353ff434fd00d8fa5a44734b3625a06eeb2a3fb468da7dfae134@%3Ccommits.karaf.apache.org%3E [No Types Assigned]
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r7d5e518088e2e778928b02bcd3be3b948b59acefe2f0ebb57ec2ebb0@%3Ccommits.karaf.apache.org%3E [No Types Assigned]

CVE Modified by Pivotal Software, Inc. 7/20/2021 7:15:24 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://www.oracle.com//security-alerts/cpujul2021.html [No Types Assigned]

CVE Modified by Pivotal Software, Inc. 3/17/2021 6:15:12 AM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/rded5291e25a4c4085a6d43cf262e479140198bf4eabb84986e0a1ef3@%3Cdev.rocketmq.apache.org%3E [No Types Assigned]

CVE Modified by Pivotal Software, Inc. 10/19/2020 3:15:15 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r1c679c43fa4f7846d748a937955c7921436d1b315445978254442163@%3Ccommits.ambari.apache.org%3E [No Types Assigned]
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r8b496b1743d128e6861ee0ed3c3c48cc56c505b38f84fa5baf7ae33a@%3Cdev.ambari.apache.org%3E [No Types Assigned]
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/r9f13cccb214495e14648d2c9b8f2c6072fd5219e74502dd35ede81e1@%3Cdev.ambari.apache.org%3E [No Types Assigned]

Initial Analysis 1/24/2020 4:57:29 PM

Action Type Old Value New Value
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:a:pivotal_software:spring_framework:*:*:*:*:*:*:*:* versions from (including) 5.2.0 up to (excluding) 5.2.3
     *cpe:2.3:a:pivotal_software:spring_security:*:*:*:*:*:*:*:* versions from (including) 5.0.0 up to (excluding) 5.0.16
     *cpe:2.3:a:pivotal_software:spring_security:*:*:*:*:*:*:*:* versions from (including) 5.1.0 up to (excluding) 5.1.13
Added CVSS V2

								
							
							
						
NIST (AV:N/AC:H/Au:N/C:C/I:C/A:C)
Added CVSS V2 Metadata

								
							
							
						
Victim must voluntarily interact with attack mechanism
Added CVSS V3.1

								
							
							
						
NIST AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Added CWE

								
							
							
						
NIST CWE-494
Changed Reference Type
https://pivotal.io/security/cve-2020-5398 No Types Assigned
https://pivotal.io/security/cve-2020-5398 Vendor Advisory

CVE Modified by Pivotal Software, Inc. 4/10/2020 4:15:11 PM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/rc05acaacad089613e9642f939b3a44f7199b5537493945c3e045287f@%3Cdev.geode.apache.org%3E [No Types Assigned]

CVE Modified by Pivotal Software, Inc. 2/20/2020 11:15:11 AM

Action Type Old Value New Value
Added Reference

								
							
							
						
https://lists.apache.org/thread.html/rf8dc72b974ee74f17bce661ea7d124e733a1f4c4f236354ac0cf48e8@%3Ccommits.camel.apache.org%3E [No Types Assigned]