Spring Framework — универсальный фреймворк с открытым исходным кодом для Java-платформы.
Релизный цикл, информация об уязвимостях
График релизов
Количество 236
GHSA-rqph-vqwm-22vc
Allocation of Resources Without Limits or Throttling in Spring Framework
GHSA-hh26-6xwr-ggv7
Denial of service in Spring Framework

CVE-2022-22971
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
CVE-2022-22971
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupp ...

CVE-2022-22970
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.
CVE-2022-22970
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupp ...

CVE-2022-22971
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

CVE-2022-22970
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

CVE-2022-22970
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

CVE-2022-22971
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
GHSA-rqph-vqwm-22vc Allocation of Resources Without Limits or Throttling in Spring Framework | CVSS3: 6.5 | 1% Низкий | около 3 лет назад | |
GHSA-hh26-6xwr-ggv7 Denial of service in Spring Framework | CVSS3: 7.5 | 0% Низкий | около 3 лет назад | |
![]() | CVE-2022-22971 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user. | CVSS3: 6.5 | 1% Низкий | около 3 лет назад |
CVE-2022-22971 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupp ... | CVSS3: 6.5 | 1% Низкий | около 3 лет назад | |
![]() | CVE-2022-22970 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object. | CVSS3: 5.3 | 0% Низкий | около 3 лет назад |
CVE-2022-22970 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupp ... | CVSS3: 5.3 | 0% Низкий | около 3 лет назад | |
![]() | CVE-2022-22971 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user. | CVSS3: 6.5 | 1% Низкий | около 3 лет назад |
![]() | CVE-2022-22970 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object. | CVSS3: 5.3 | 0% Низкий | около 3 лет назад |
![]() | CVE-2022-22970 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object. | CVSS3: 5.3 | 0% Низкий | около 3 лет назад |
![]() | CVE-2022-22971 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user. | CVSS3: 6.5 | 1% Низкий | около 3 лет назад |
Уязвимостей на страницу