Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-22737

Опубликовано: 20 мар. 2026
Источник: nvd
CVSS3: 5.9
EPSS Низкий

Описание

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

EPSS

Процентиль: 20%
0.00063
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
redhat
12 дней назад

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVSS3: 5.9
debian
12 дней назад

Use of Java scripting engine enabled (e.g. JRuby, Jython) template vie ...

CVSS3: 5.9
github
12 дней назад

Spring Framework Improper Path Limitation with Script View Templates

EPSS

Процентиль: 20%
0.00063
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-22