Логотип exploitDog
product: "spring_framework"
Консоль
Логотип exploitDog

exploitDog

product: "spring_framework"
Spring Framework

Spring Frameworkуниверсальный фреймворк с открытым исходным кодом для Java-платформы.

Релизный цикл, информация об уязвимостях

Продукт: Spring Framework
Вендор: VMware

График релизов

6.16.220232024202520262027

Недавние уязвимости Spring Framework

Количество 241

github логотип

GHSA-p5hg-3xm3-gcjg

больше 6 лет назад

Spring Framework allows applications to expose STOMP over WebSocket endpoints

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-cxrj-66c5-9fmh

больше 6 лет назад

Spring Framework when used in combination with any versions of Spring Security contains an authorization bypass

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-rcpf-vj53-7h2m

больше 6 лет назад

Denial of Service in org.springframework:spring-core

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-v596-fwhq-8x48

больше 6 лет назад

Improper Input Validation in org.springframework.security:spring-security-core, org.springframework.security:spring-security-core , and org.springframework:spring-core

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-f26x-pr96-vw86

больше 6 лет назад

Moderate severity vulnerability that affects org.springframework:spring-core

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-9gcm-f4x3-8jpw

больше 6 лет назад

Spring Framework Cross Site Tracing (XST)

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2018-15756

больше 6 лет назад

Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an org.springframework.core.io.Resource. A malicious user (or attacker) can add a range header with a high number of ranges, or with wide ranges that overlap, or both, for a denial of service attack. This vulnerability affects applications that depend on either spring-webmvc or spring-webflux. Such applications must also have a registration for serving static resources (e.g. JS, CSS, images, and others), or have an annotated controller that returns an org.springframework.core.io.Resource. Spring Boot applications that depend on spring-boot-starter-web or spring-boot-starter-webflux are ready to serve static resources out of the box and are therefore vulnerable.

CVSS3: 3.1
EPSS: Средний
github логотип

GHSA-2m8h-fgr8-2q9w

больше 6 лет назад

Pivotal Spring Framework Paths provided to the ResourceServlet were not properly sanitized

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2018-11040

почти 7 лет назад

Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not enabled by default in Spring Framework nor Spring Boot, however, when MappingJackson2JsonView is configured in an application, JSONP support is automatically ready to use through the "jsonp" and "callback" JSONP parameters, enabling cross-domain requests.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2018-11040

почти 7 лет назад

Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3 ...

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-p5hg-3xm3-gcjg

Spring Framework allows applications to expose STOMP over WebSocket endpoints

CVSS3: 9.8
89%
Высокий
больше 6 лет назад
github логотип
GHSA-cxrj-66c5-9fmh

Spring Framework when used in combination with any versions of Spring Security contains an authorization bypass

CVSS3: 8.8
0%
Низкий
больше 6 лет назад
github логотип
GHSA-rcpf-vj53-7h2m

Denial of Service in org.springframework:spring-core

CVSS3: 6.5
1%
Низкий
больше 6 лет назад
github логотип
GHSA-v596-fwhq-8x48

Improper Input Validation in org.springframework.security:spring-security-core, org.springframework.security:spring-security-core , and org.springframework:spring-core

CVSS3: 5.3
1%
Низкий
больше 6 лет назад
github логотип
GHSA-f26x-pr96-vw86

Moderate severity vulnerability that affects org.springframework:spring-core

CVSS3: 5.9
8%
Низкий
больше 6 лет назад
github логотип
GHSA-9gcm-f4x3-8jpw

Spring Framework Cross Site Tracing (XST)

CVSS3: 5.9
3%
Низкий
больше 6 лет назад
redhat логотип
CVE-2018-15756

Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an org.springframework.core.io.Resource. A malicious user (or attacker) can add a range header with a high number of ranges, or with wide ranges that overlap, or both, for a denial of service attack. This vulnerability affects applications that depend on either spring-webmvc or spring-webflux. Such applications must also have a registration for serving static resources (e.g. JS, CSS, images, and others), or have an annotated controller that returns an org.springframework.core.io.Resource. Spring Boot applications that depend on spring-boot-starter-web or spring-boot-starter-webflux are ready to serve static resources out of the box and are therefore vulnerable.

CVSS3: 3.1
14%
Средний
больше 6 лет назад
github логотип
GHSA-2m8h-fgr8-2q9w

Pivotal Spring Framework Paths provided to the ResourceServlet were not properly sanitized

CVSS3: 7.5
5%
Низкий
больше 6 лет назад
nvd логотип
CVE-2018-11040

Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not enabled by default in Spring Framework nor Spring Boot, however, when MappingJackson2JsonView is configured in an application, JSONP support is automatically ready to use through the "jsonp" and "callback" JSONP parameters, enabling cross-domain requests.

CVSS3: 7.5
8%
Низкий
почти 7 лет назад
debian логотип
CVE-2018-11040

Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3 ...

CVSS3: 7.5
8%
Низкий
почти 7 лет назад

Уязвимостей на страницу


Поделиться