Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vqgp-pf68-6947

Опубликовано: 09 июн. 2026
Источник: github
Github: Прошло ревью
CVSS3: 4.8

Описание

Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL

Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL.

Affected versions: Spring Framework 5.3.0 through 5.3.48.

Пакеты

Наименование

org.springframework:spring-webflux

maven
Затронутые версииВерсия исправления

<= 5.3.39

Отсутствует

EPSS

Процентиль: 6%
0.00166
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 4.8
ubuntu
3 месяца назад

Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48.

CVSS3: 4.8
redhat
3 месяца назад

Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48.

CVSS3: 4.8
nvd
3 месяца назад

Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48.

CVSS3: 4.8
debian
3 месяца назад

Spring WebFlux applications may be vulnerable to a security bypass whe ...

EPSS

Процентиль: 6%
0.00166
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-284