Логотип exploitDog
product: "spring_framework"
Консоль
Логотип exploitDog

exploitDog

product: "spring_framework"
Spring Framework

Spring Frameworkуниверсальный фреймворк с открытым исходным кодом для Java-платформы.

Релизный цикл, информация об уязвимостях

Продукт: Spring Framework
Вендор: VMware

График релизов

6.22024202520262027

Недавние уязвимости Spring Framework

Количество 241

github логотип

GHSA-ffvq-7w96-97p7

больше 5 лет назад

Denial of Service in Spring Framework

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-7pm4-g2qj-j85x

почти 6 лет назад

CSRF attack via CORS preflight requests with Spring MVC or Spring WebFlux

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-8wx2-9q48-vm9r

почти 6 лет назад

RFD attack via Content-Disposition header sourced from request input by Spring MVC or Spring WebFlux Application

CVSS3: 7.5
EPSS: Критический
nvd логотип

CVE-2020-5397

почти 6 лет назад

Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail authentication. However a notable exception to this are Chrome based browsers when using client certificates for authentication since Chrome sends TLS client certificates in CORS preflight requests in violation of spec requirements. No HTTP body can be sent or received as a result of this attack.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-5397

почти 6 лет назад

Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2020-5397

почти 6 лет назад

Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail authentication. However a notable exception to this are Chrome based browsers when using client certificates for authentication since Chrome sends TLS client certificates in CORS preflight requests in violation of spec requirements. No HTTP body can be sent or received as a result of this attack.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2020-5398

почти 6 лет назад

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.

CVSS3: 7.5
EPSS: Критический
debian логотип

CVE-2020-5398

почти 6 лет назад

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x pri ...

CVSS3: 7.5
EPSS: Критический
ubuntu логотип

CVE-2020-5398

почти 6 лет назад

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.

CVSS3: 7.5
EPSS: Критический
redhat логотип

CVE-2020-5397

почти 6 лет назад

Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail authentication. However a notable exception to this are Chrome based browsers when using client certificates for authentication since Chrome sends TLS client certificates in CORS preflight requests in violation of spec requirements. No HTTP body can be sent or received as a result of this attack.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-ffvq-7w96-97p7

Denial of Service in Spring Framework

CVSS3: 7.5
13%
Средний
больше 5 лет назад
github логотип
GHSA-7pm4-g2qj-j85x

CSRF attack via CORS preflight requests with Spring MVC or Spring WebFlux

CVSS3: 5.3
1%
Низкий
почти 6 лет назад
github логотип
GHSA-8wx2-9q48-vm9r

RFD attack via Content-Disposition header sourced from request input by Spring MVC or Spring WebFlux Application

CVSS3: 7.5
91%
Критический
почти 6 лет назад
nvd логотип
CVE-2020-5397

Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail authentication. However a notable exception to this are Chrome based browsers when using client certificates for authentication since Chrome sends TLS client certificates in CORS preflight requests in violation of spec requirements. No HTTP body can be sent or received as a result of this attack.

CVSS3: 5.3
1%
Низкий
почти 6 лет назад
debian логотип
CVE-2020-5397

Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF ...

CVSS3: 5.3
1%
Низкий
почти 6 лет назад
ubuntu логотип
CVE-2020-5397

Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail authentication. However a notable exception to this are Chrome based browsers when using client certificates for authentication since Chrome sends TLS client certificates in CORS preflight requests in violation of spec requirements. No HTTP body can be sent or received as a result of this attack.

CVSS3: 5.3
1%
Низкий
почти 6 лет назад
nvd логотип
CVE-2020-5398

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.

CVSS3: 7.5
91%
Критический
почти 6 лет назад
debian логотип
CVE-2020-5398

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x pri ...

CVSS3: 7.5
91%
Критический
почти 6 лет назад
ubuntu логотип
CVE-2020-5398

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.

CVSS3: 7.5
91%
Критический
почти 6 лет назад
redhat логотип
CVE-2020-5397

Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail authentication. However a notable exception to this are Chrome based browsers when using client certificates for authentication since Chrome sends TLS client certificates in CORS preflight requests in violation of spec requirements. No HTTP body can be sent or received as a result of this attack.

CVSS3: 5.3
1%
Низкий
почти 6 лет назад

Уязвимостей на страницу


Поделиться