Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Spring Framework

Spring Frameworkуниверсальный фреймворк с открытым исходным кодом для Java-платформы.

Релизный цикл, информация об уязвимостях

Продукт: Spring Framework
Вендор: VMware

График релизов

7.02025202620272028

Недавние уязвимости Spring Framework

Количество 422

nvd логотип

CVE-2023-20861

больше 3 лет назад

In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2023-20861

больше 3 лет назад

In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2023-20861

больше 3 лет назад

In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2023-20860

больше 3 лет назад

Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-rfmp-97jj-h8m6

больше 4 лет назад

Improper Output Neutralization for Logs in Spring Framework

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-gfwj-fwqj-fp3v

больше 4 лет назад

Improper Privilege Management in Spring Framework

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-4wrc-f8pq-fpqp

больше 4 лет назад

Pivotal Spring Framework contains unsafe Java deserialization methods

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-vpr3-f594-mg5g

больше 4 лет назад

Improper Control of Generation of Code ('Code Injection') in Spring Framework

EPSS: Средний
github логотип

GHSA-wv88-pf73-x22p

больше 4 лет назад

Improper Neutralization of Directives in Dynamically Evaluated Code in Spring Framework

EPSS: Средний
github логотип

GHSA-f866-m9mv-2xr3

больше 4 лет назад

Spring Framework and Spring Security vulnerable to Deserialization of Untrusted Data

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2023-20861

In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
ubuntu логотип
CVE-2023-20861

In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2023-20861

In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.

CVSS3: 5.3
1%
Низкий
больше 3 лет назад
redhat логотип
CVE-2023-20860

Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.

CVSS3: 7.5
4%
Низкий
больше 3 лет назад
github логотип
GHSA-rfmp-97jj-h8m6

Improper Output Neutralization for Logs in Spring Framework

CVSS3: 4.3
1%
Низкий
больше 4 лет назад
github логотип
GHSA-gfwj-fwqj-fp3v

Improper Privilege Management in Spring Framework

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-4wrc-f8pq-fpqp

Pivotal Spring Framework contains unsafe Java deserialization methods

CVSS3: 9.8
32%
Средний
больше 4 лет назад
github логотип
GHSA-vpr3-f594-mg5g

Improper Control of Generation of Code ('Code Injection') in Spring Framework

52%
Средний
больше 4 лет назад
github логотип
GHSA-wv88-pf73-x22p

Improper Neutralization of Directives in Dynamically Evaluated Code in Spring Framework

12%
Средний
больше 4 лет назад
github логотип
GHSA-f866-m9mv-2xr3

Spring Framework and Spring Security vulnerable to Deserialization of Untrusted Data

9%
Низкий
больше 4 лет назад

Уязвимостей на страницу


Поделиться