---
id: CVE-2017-8039
title: An issue was discovered in Pivotal Spring Web Flow through 2.4.5
summary: >-
  An issue was discovered in Pivotal Spring Web Flow through 2.4.5. Applications
  that do not change the value of the MvcViewFactoryCreator useSpringBinding
  property which is disabled by default (i.e., set to 'false') can be vulnerable
  to m…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-1188
vendor: broadcom
product: spring_web_flow
affected:
  - spring_web_flow = 2.4.0
  - spring_web_flow = 2.4.1
  - spring_web_flow = 2.4.2
  - spring_web_flow = 2.4.4
  - spring_web_flow = 2.4.5
published: '2017-11-27'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T17:13:05.477'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2017-8039'
references:
  - url: 'http://www.securityfocus.com/bid/100849'
    label: security_alert@emc.com
  - url: 'https://pivotal.io/security/cve-2017-8039'
    label: security_alert@emc.com
  - url: 'http://www.securityfocus.com/bid/100849'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://pivotal.io/security/cve-2017-8039'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00963
epssPercentile: 0.60194
ingestedAt: '2026-09-08T18:07:34.872Z'
---

## Overview

An issue was discovered in Pivotal Spring Web Flow through 2.4.5. Applications that do not change the value of the MvcViewFactoryCreator useSpringBinding property which is disabled by default (i.e., set to 'false') can be vulnerable to malicious EL expressions in view states that process form submissions but do not have a sub-element to declare explicit data binding property mappings. NOTE: this issue exists because of an incomplete fix for CVE-2017-4971.

## Affected

- `spring_web_flow = 2.4.0`
- `spring_web_flow = 2.4.1`
- `spring_web_flow = 2.4.2`
- `spring_web_flow = 2.4.4`
- `spring_web_flow = 2.4.5`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
