Логотип exploitDog
product: "spring_framework"
Консоль
Логотип exploitDog

exploitDog

product: "spring_framework"
Spring Framework

Spring Frameworkуниверсальный фреймворк с открытым исходным кодом для Java-платформы.

Релизный цикл, информация об уязвимостях

Продукт: Spring Framework
Вендор: VMware

График релизов

6.16.220232024202520262027

Недавние уязвимости Spring Framework

Количество 236

github логотип

GHSA-rqph-vqwm-22vc

около 3 лет назад

Allocation of Resources Without Limits or Throttling in Spring Framework

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-hh26-6xwr-ggv7

около 3 лет назад

Denial of service in Spring Framework

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2022-22971

около 3 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2022-22971

около 3 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupp ...

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2022-22970

около 3 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2022-22970

около 3 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupp ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2022-22971

около 3 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2022-22970

около 3 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2022-22970

около 3 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2022-22971

около 3 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-rqph-vqwm-22vc

Allocation of Resources Without Limits or Throttling in Spring Framework

CVSS3: 6.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-hh26-6xwr-ggv7

Denial of service in Spring Framework

CVSS3: 7.5
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-22971

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

CVSS3: 6.5
1%
Низкий
около 3 лет назад
debian логотип
CVE-2022-22971

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupp ...

CVSS3: 6.5
1%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-22970

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-22970

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupp ...

CVSS3: 5.3
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-22971

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

CVSS3: 6.5
1%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-22970

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-22970

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-22971

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

CVSS3: 6.5
1%
Низкий
около 3 лет назад

Уязвимостей на страницу


Поделиться