Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-40972

Опубликовано: 28 апр. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the attacker determining the secret and uploading changed classes, thereby achieving remote code execution in the remote application.

Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); DevTools remote secret comparison. Versions that are no longer supported are also affected per vendor advisory.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*
Версия до 2.7.33 (исключая)
cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*
Версия от 3.3.0 (включая) до 3.3.19 (исключая)
cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*
Версия от 3.4.0 (включая) до 3.4.16 (исключая)
cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*
Версия от 3.5.0 (включая) до 3.5.14 (исключая)
cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*
Версия от 4.0.0 (включая) до 4.0.6 (исключая)

EPSS

Процентиль: 18%
0.00262
Низкий

7.5 High

CVSS3

Дефекты

CWE-208

Связанные уязвимости

CVSS3: 7.5
redhat
4 месяца назад

An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the attacker determining the secret and uploading changed classes, thereby achieving remote code execution in the remote application. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); DevTools remote secret comparison. Versions that are no longer supported are also affected per vendor advisory.

CVSS3: 7.5
github
4 месяца назад

Spring Boot DevTools remote secret comparison is vulnerable to timing attacks

EPSS

Процентиль: 18%
0.00262
Низкий

7.5 High

CVSS3

Дефекты

CWE-208