Spring Framework — универсальный фреймворк с открытым исходным кодом для Java-платформы.
Релизный цикл, информация об уязвимостях
График релизов
Количество 422
CVE-2022-22971
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupp ...
CVE-2022-22971
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
CVE-2022-22970
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupp ...
CVE-2022-22970
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
CVE-2022-22970
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
CVE-2022-22971
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
CVE-2022-22971
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
CVE-2022-22970
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
GHSA-xjrf-8x4f-43h4
Improper Neutralization of Input During Web Page Generation in Spring Framework
GHSA-wjjr-h4wh-w6vv
Spring Framework Inefficient Regular Expression Complexity
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2022-22971 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupp ... | CVSS3: 6.5 | 3% Низкий | больше 4 лет назад | |
CVE-2022-22971 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user. | CVSS3: 6.5 | 3% Низкий | больше 4 лет назад | |
CVE-2022-22970 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupp ... | CVSS3: 5.3 | 2% Низкий | больше 4 лет назад | |
CVE-2022-22970 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object. | CVSS3: 5.3 | 2% Низкий | больше 4 лет назад | |
CVE-2022-22970 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object. | CVSS3: 5.3 | 2% Низкий | больше 4 лет назад | |
CVE-2022-22971 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user. | CVSS3: 6.5 | 3% Низкий | больше 4 лет назад | |
CVE-2022-22971 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user. | CVSS3: 6.5 | 3% Низкий | больше 4 лет назад | |
CVE-2022-22970 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object. | CVSS3: 5.3 | 2% Низкий | больше 4 лет назад | |
GHSA-xjrf-8x4f-43h4 Improper Neutralization of Input During Web Page Generation in Spring Framework | CVSS3: 5.4 | 2% Низкий | больше 4 лет назад | |
GHSA-wjjr-h4wh-w6vv Spring Framework Inefficient Regular Expression Complexity | 3% Низкий | больше 4 лет назад |
Уязвимостей на страницу