---
id: CVE-2017-4971
title: An issue was discovered in Pivotal Spring Web Flow through 2.4.4
summary: >-
  An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications
  that do not change the value of the MvcViewFactoryCreator useSpringBinding
  property which is disabled by default (i.e., set to 'false') can be vulnerable
  to m…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-1188
vendor: broadcom
product: spring_web_flow
affected:
  - spring_web_flow = 2.4.0
  - spring_web_flow = 2.4.1
  - spring_web_flow = 2.4.2
  - spring_web_flow = 2.4.4
published: '2017-06-13'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T17:13:05.477'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2017-4971'
references:
  - url: 'http://www.securityfocus.com/bid/98785'
    label: security_alert@emc.com
  - url: 'https://jira.spring.io/browse/SWF-1700'
    label: security_alert@emc.com
  - url: 'https://pivotal.io/security/cve-2017-4971'
    label: security_alert@emc.com
  - url: 'http://www.securityfocus.com/bid/98785'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://jira.spring.io/browse/SWF-1700'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://pivotal.io/security/cve-2017-4971'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.11836
epssPercentile: 0.95957
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/cved-sources/cve-2017-4971'
  checkedAt: '2026-09-21T15:23:36.378Z'
exploitAvailable: true
ingestedAt: '2026-09-08T18:07:34.872Z'
---

## Overview

An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that process form submissions but do not have a sub-element to declare explicit data binding property mappings.

## Affected

- `spring_web_flow = 2.4.0`
- `spring_web_flow = 2.4.1`
- `spring_web_flow = 2.4.2`
- `spring_web_flow = 2.4.4`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
