Логотип exploitDog
product: "spring_framework"
Консоль
Логотип exploitDog

exploitDog

product: "spring_framework"
Spring Framework

Spring Frameworkуниверсальный фреймворк с открытым исходным кодом для Java-платформы.

Релизный цикл, информация об уязвимостях

Продукт: Spring Framework
Вендор: VMware

График релизов

6.27.020242025202620272028

Недавние уязвимости Spring Framework

Количество 241

redhat логотип

CVE-2020-5398

около 6 лет назад

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.

CVSS3: 8
EPSS: Критический
nvd логотип

CVE-2013-6430

около 6 лет назад

The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape certain characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a (1) line separator or (2) paragraph separator Unicode character or (3) left or (4) right angle bracket.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2013-6430

около 6 лет назад

The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtil ...

CVSS3: 5.4
EPSS: Низкий
ubuntu логотип

CVE-2013-6430

около 6 лет назад

The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape certain characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a (1) line separator or (2) paragraph separator Unicode character or (3) left or (4) right angle bracket.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2016-1000027

около 6 лет назад

Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2016-1000027

около 6 лет назад

Pivotal Spring Framework through 5.3.16 suffers from a potential remot ...

CVSS3: 9.8
EPSS: Средний
ubuntu логотип

CVE-2016-1000027

около 6 лет назад

Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-27xw-p8v6-9jjr

около 7 лет назад

Spring Security vulnerable to Authorization Bypass

CVSS3: 7.4
EPSS: Низкий
nvd логотип

CVE-2018-15801

около 7 лет назад

Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation. In order to be impacted, the same private key for an honest issuer and a malicious user must be used when signing JWTs. In that case, a malicious user could fashion signed JWTs with the malicious issuer URL that may be granted for the honest issuer.

CVSS3: 7.4
EPSS: Низкий
debian логотип

CVE-2018-15801

около 7 лет назад

Spring Security versions 5.1.x prior to 5.1.2 contain an authorization ...

CVSS3: 7.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2020-5398

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.

CVSS3: 8
90%
Критический
около 6 лет назад
nvd логотип
CVE-2013-6430

The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape certain characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a (1) line separator or (2) paragraph separator Unicode character or (3) left or (4) right angle bracket.

CVSS3: 5.4
0%
Низкий
около 6 лет назад
debian логотип
CVE-2013-6430

The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtil ...

CVSS3: 5.4
0%
Низкий
около 6 лет назад
ubuntu логотип
CVE-2013-6430

The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape certain characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a (1) line separator or (2) paragraph separator Unicode character or (3) left or (4) right angle bracket.

CVSS3: 5.4
0%
Низкий
около 6 лет назад
nvd логотип
CVE-2016-1000027

Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.

CVSS3: 9.8
43%
Средний
около 6 лет назад
debian логотип
CVE-2016-1000027

Pivotal Spring Framework through 5.3.16 suffers from a potential remot ...

CVSS3: 9.8
43%
Средний
около 6 лет назад
ubuntu логотип
CVE-2016-1000027

Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data.

CVSS3: 9.8
43%
Средний
около 6 лет назад
github логотип
GHSA-27xw-p8v6-9jjr

Spring Security vulnerable to Authorization Bypass

CVSS3: 7.4
0%
Низкий
около 7 лет назад
nvd логотип
CVE-2018-15801

Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation. In order to be impacted, the same private key for an honest issuer and a malicious user must be used when signing JWTs. In that case, a malicious user could fashion signed JWTs with the malicious issuer URL that may be granted for the honest issuer.

CVSS3: 7.4
0%
Низкий
около 7 лет назад
debian логотип
CVE-2018-15801

Spring Security versions 5.1.x prior to 5.1.2 contain an authorization ...

CVSS3: 7.4
0%
Низкий
около 7 лет назад

Уязвимостей на страницу


Поделиться