Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Spring Framework

Spring Frameworkуниверсальный фреймворк с открытым исходным кодом для Java-платформы.

Релизный цикл, информация об уязвимостях

Продукт: Spring Framework
Вендор: VMware

График релизов

7.02025202620272028

Недавние уязвимости Spring Framework

Количество 422

debian логотип

CVE-2022-22971

больше 4 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupp ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-22971

больше 4 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-22970

больше 4 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupp ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2022-22970

больше 4 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2022-22970

больше 4 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2022-22971

больше 4 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-22971

больше 4 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2022-22970

больше 4 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-xjrf-8x4f-43h4

больше 4 лет назад

Improper Neutralization of Input During Web Page Generation in Spring Framework

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-wjjr-h4wh-w6vv

больше 4 лет назад

Spring Framework Inefficient Regular Expression Complexity

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2022-22971

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupp ...

CVSS3: 6.5
3%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-22971

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

CVSS3: 6.5
3%
Низкий
больше 4 лет назад
debian логотип
CVE-2022-22970

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupp ...

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
nvd логотип
CVE-2022-22970

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2022-22970

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2022-22971

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

CVSS3: 6.5
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-22971

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

CVSS3: 6.5
3%
Низкий
больше 4 лет назад
redhat логотип
CVE-2022-22970

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

CVSS3: 5.3
2%
Низкий
больше 4 лет назад
github логотип
GHSA-xjrf-8x4f-43h4

Improper Neutralization of Input During Web Page Generation in Spring Framework

CVSS3: 5.4
2%
Низкий
больше 4 лет назад
github логотип
GHSA-wjjr-h4wh-w6vv

Spring Framework Inefficient Regular Expression Complexity

3%
Низкий
больше 4 лет назад

Уязвимостей на страницу


Поделиться