Spring Framework — универсальный фреймворк с открытым исходным кодом для Java-платформы.
Релизный цикл, информация об уязвимостях
График релизов
Количество 241
GHSA-f93f-g33r-8pcp
Improper Restriction of XML External Entity Reference in Spring Framework
GHSA-g6hf-f9cq-q7w7
Cross-Site Request Forgery in Spring Framework
GHSA-vp63-rrcm-9mph
Missing XML Validation in Spring Framework
GHSA-rp4p-g69r-438x
Cross-Site Request Forgery in Spring Framework
GHSA-8cmm-qj8g-fcp6
Cross-Site Request Forgery in Spring Framework
GHSA-rqph-vqwm-22vc
Allocation of Resources Without Limits or Throttling in Spring Framework
GHSA-hh26-6xwr-ggv7
Denial of service in Spring Framework

CVE-2022-22971
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
CVE-2022-22971
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupp ...

CVE-2022-22970
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
GHSA-f93f-g33r-8pcp Improper Restriction of XML External Entity Reference in Spring Framework | CVSS3: 8.8 | 0% Низкий | около 3 лет назад | |
GHSA-g6hf-f9cq-q7w7 Cross-Site Request Forgery in Spring Framework | 58% Средний | около 3 лет назад | ||
GHSA-vp63-rrcm-9mph Missing XML Validation in Spring Framework | 1% Низкий | около 3 лет назад | ||
GHSA-rp4p-g69r-438x Cross-Site Request Forgery in Spring Framework | 84% Высокий | около 3 лет назад | ||
GHSA-8cmm-qj8g-fcp6 Cross-Site Request Forgery in Spring Framework | 35% Средний | около 3 лет назад | ||
GHSA-rqph-vqwm-22vc Allocation of Resources Without Limits or Throttling in Spring Framework | CVSS3: 6.5 | 0% Низкий | около 3 лет назад | |
GHSA-hh26-6xwr-ggv7 Denial of service in Spring Framework | CVSS3: 7.5 | 0% Низкий | около 3 лет назад | |
![]() | CVE-2022-22971 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user. | CVSS3: 6.5 | 0% Низкий | около 3 лет назад |
CVE-2022-22971 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupp ... | CVSS3: 6.5 | 0% Низкий | около 3 лет назад | |
![]() | CVE-2022-22970 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object. | CVSS3: 5.3 | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу