CVE-2014-1904: Pivotal Software Spring Framework

Medium severity, CVSS 4.3. EPSS: 6.9% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the requested URI in a default action.

Affected products

  • Pivotal Software Spring Framework: from 3.0.0, before 3.2.8 (fixed in 3.2.8); from 4.0.0, before 4.0.2 (fixed in 4.0.2)

Published 2014-03-20. Last modified 2026-06-17.