Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Spring Framework

Spring Frameworkуниверсальный фреймворк с открытым исходным кодом для Java-платформы.

Релизный цикл, информация об уязвимостях

Продукт: Spring Framework
Вендор: VMware

График релизов

7.02025202620272028

Недавние уязвимости Spring Framework

Количество 422

ubuntu логотип

CVE-2026-22737

6 месяцев назад

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2026-22737

6 месяцев назад

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2026-22735

6 месяцев назад

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-4gc7-5j7h-4qph

почти 2 года назад

Spring Framework DataBinder Case Sensitive Match Exception

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2024-38820

почти 2 года назад

The fix for CVE-2022-22968 made disallowedFieldspatterns in DataBinder ...

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2024-38820

почти 2 года назад

The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.

CVSS3: 3.1
EPSS: Низкий
ubuntu логотип

CVE-2024-38820

почти 2 года назад

The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-9cmq-m9j5-mvww

около 2 лет назад

Spring Framework vulnerable to Denial of Service

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2024-38808

около 2 лет назад

In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported vers ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2024-38808

около 2 лет назад

In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an application is vulnerable when the following is true: * The application evaluates user-supplied SpEL expressions.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
ubuntu логотип
CVE-2026-22737

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVSS3: 5.9
0%
Низкий
6 месяцев назад
redhat логотип
CVE-2026-22737

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVSS3: 6.5
0%
Низкий
6 месяцев назад
redhat логотип
CVE-2026-22735

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE). This issue affects Spring Foundation: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVSS3: 2.6
0%
Низкий
6 месяцев назад
github логотип
GHSA-4gc7-5j7h-4qph

Spring Framework DataBinder Case Sensitive Match Exception

CVSS3: 5.3
1%
Низкий
почти 2 года назад
debian логотип
CVE-2024-38820

The fix for CVE-2022-22968 made disallowedFieldspatterns in DataBinder ...

CVSS3: 3.1
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-38820

The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.

CVSS3: 3.1
1%
Низкий
почти 2 года назад
ubuntu логотип
CVE-2024-38820

The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.

CVSS3: 3.1
1%
Низкий
почти 2 года назад
github логотип
GHSA-9cmq-m9j5-mvww

Spring Framework vulnerable to Denial of Service

CVSS3: 4.3
1%
Низкий
около 2 лет назад
debian логотип
CVE-2024-38808

In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported vers ...

CVSS3: 4.3
1%
Низкий
около 2 лет назад
nvd логотип
CVE-2024-38808

In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition. Specifically, an application is vulnerable when the following is true: * The application evaluates user-supplied SpEL expressions.

CVSS3: 4.3
1%
Низкий
около 2 лет назад

Уязвимостей на страницу


Поделиться