Логотип exploitDog
product: "spring_framework"
Консоль
Логотип exploitDog

exploitDog

product: "spring_framework"
Spring Framework

Spring Frameworkуниверсальный фреймворк с открытым исходным кодом для Java-платформы.

Релизный цикл, информация об уязвимостях

Продукт: Spring Framework
Вендор: VMware

График релизов

6.16.220232024202520262027

Недавние уязвимости Spring Framework

Количество 241

github логотип

GHSA-ffvq-7w96-97p7

около 5 лет назад

Denial of Service in Spring Framework

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-7pm4-g2qj-j85x

больше 5 лет назад

CSRF attack via CORS preflight requests with Spring MVC or Spring WebFlux

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-8wx2-9q48-vm9r

больше 5 лет назад

RFD attack via Content-Disposition header sourced from request input by Spring MVC or Spring WebFlux Application

CVSS3: 7.5
EPSS: Критический
nvd логотип

CVE-2020-5397

больше 5 лет назад

Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail authentication. However a notable exception to this are Chrome based browsers when using client certificates for authentication since Chrome sends TLS client certificates in CORS preflight requests in violation of spec requirements. No HTTP body can be sent or received as a result of this attack.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2020-5397

больше 5 лет назад

Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2020-5397

больше 5 лет назад

Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail authentication. However a notable exception to this are Chrome based browsers when using client certificates for authentication since Chrome sends TLS client certificates in CORS preflight requests in violation of spec requirements. No HTTP body can be sent or received as a result of this attack.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2020-5398

больше 5 лет назад

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.

CVSS3: 7.5
EPSS: Критический
debian логотип

CVE-2020-5398

больше 5 лет назад

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x pri ...

CVSS3: 7.5
EPSS: Критический
ubuntu логотип

CVE-2020-5398

больше 5 лет назад

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.

CVSS3: 7.5
EPSS: Критический
redhat логотип

CVE-2020-5397

больше 5 лет назад

Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail authentication. However a notable exception to this are Chrome based browsers when using client certificates for authentication since Chrome sends TLS client certificates in CORS preflight requests in violation of spec requirements. No HTTP body can be sent or received as a result of this attack.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-ffvq-7w96-97p7

Denial of Service in Spring Framework

CVSS3: 7.5
14%
Средний
около 5 лет назад
github логотип
GHSA-7pm4-g2qj-j85x

CSRF attack via CORS preflight requests with Spring MVC or Spring WebFlux

CVSS3: 5.3
1%
Низкий
больше 5 лет назад
github логотип
GHSA-8wx2-9q48-vm9r

RFD attack via Content-Disposition header sourced from request input by Spring MVC or Spring WebFlux Application

CVSS3: 7.5
91%
Критический
больше 5 лет назад
nvd логотип
CVE-2020-5397

Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail authentication. However a notable exception to this are Chrome based browsers when using client certificates for authentication since Chrome sends TLS client certificates in CORS preflight requests in violation of spec requirements. No HTTP body can be sent or received as a result of this attack.

CVSS3: 5.3
1%
Низкий
больше 5 лет назад
debian логотип
CVE-2020-5397

Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF ...

CVSS3: 5.3
1%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-5397

Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail authentication. However a notable exception to this are Chrome based browsers when using client certificates for authentication since Chrome sends TLS client certificates in CORS preflight requests in violation of spec requirements. No HTTP body can be sent or received as a result of this attack.

CVSS3: 5.3
1%
Низкий
больше 5 лет назад
nvd логотип
CVE-2020-5398

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.

CVSS3: 7.5
91%
Критический
больше 5 лет назад
debian логотип
CVE-2020-5398

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x pri ...

CVSS3: 7.5
91%
Критический
больше 5 лет назад
ubuntu логотип
CVE-2020-5398

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.

CVSS3: 7.5
91%
Критический
больше 5 лет назад
redhat логотип
CVE-2020-5397

Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail authentication. However a notable exception to this are Chrome based browsers when using client certificates for authentication since Chrome sends TLS client certificates in CORS preflight requests in violation of spec requirements. No HTTP body can be sent or received as a result of this attack.

CVSS3: 5.3
1%
Низкий
больше 5 лет назад

Уязвимостей на страницу


Поделиться