Spring Framework — универсальный фреймворк с открытым исходным кодом для Java-платформы.
Релизный цикл, информация об уязвимостях
График релизов
Количество 241
CVE-2022-22970
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupp ...

CVE-2022-22971
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

CVE-2022-22970
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

CVE-2022-22970
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

CVE-2022-22971
In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.
GHSA-xjrf-8x4f-43h4
Improper Neutralization of Input During Web Page Generation in Spring Framework
GHSA-wjjr-h4wh-w6vv
Spring Framework Inefficient Regular Expression Complexity
GHSA-g5mm-vmx4-3rg7
Improper handling of case sensitivity in Spring Framework

CVE-2022-22968
In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path.
CVE-2022-22968
In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
---|---|---|---|---|
CVE-2022-22970 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupp ... | CVSS3: 5.3 | 0% Низкий | около 3 лет назад | |
![]() | CVE-2022-22971 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user. | CVSS3: 6.5 | 0% Низкий | около 3 лет назад |
![]() | CVE-2022-22970 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object. | CVSS3: 5.3 | 0% Низкий | около 3 лет назад |
![]() | CVE-2022-22970 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object. | CVSS3: 5.3 | 0% Низкий | около 3 лет назад |
![]() | CVE-2022-22971 In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user. | CVSS3: 6.5 | 0% Низкий | около 3 лет назад |
GHSA-xjrf-8x4f-43h4 Improper Neutralization of Input During Web Page Generation in Spring Framework | CVSS3: 5.4 | 0% Низкий | около 3 лет назад | |
GHSA-wjjr-h4wh-w6vv Spring Framework Inefficient Regular Expression Complexity | 1% Низкий | больше 3 лет назад | ||
GHSA-g5mm-vmx4-3rg7 Improper handling of case sensitivity in Spring Framework | CVSS3: 7.5 | 23% Средний | больше 3 лет назад | |
![]() | CVE-2022-22968 In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path. | CVSS3: 5.3 | 23% Средний | больше 3 лет назад |
CVE-2022-22968 In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older ... | CVSS3: 5.3 | 23% Средний | больше 3 лет назад |
Уязвимостей на страницу