Логотип exploitDog
product: "spring_framework"
Консоль
Логотип exploitDog

exploitDog

product: "spring_framework"
Spring Framework

Spring Frameworkуниверсальный фреймворк с открытым исходным кодом для Java-платформы.

Релизный цикл, информация об уязвимостях

Продукт: Spring Framework
Вендор: VMware

График релизов

6.22024202520262027

Недавние уязвимости Spring Framework

Количество 241

debian логотип

CVE-2022-22970

около 3 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupp ...

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2022-22971

около 3 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2022-22970

около 3 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2022-22970

около 3 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2022-22971

около 3 лет назад

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-xjrf-8x4f-43h4

около 3 лет назад

Improper Neutralization of Input During Web Page Generation in Spring Framework

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-wjjr-h4wh-w6vv

больше 3 лет назад

Spring Framework Inefficient Regular Expression Complexity

EPSS: Низкий
github логотип

GHSA-g5mm-vmx4-3rg7

больше 3 лет назад

Improper handling of case sensitivity in Spring Framework

CVSS3: 7.5
EPSS: Средний
nvd логотип

CVE-2022-22968

больше 3 лет назад

In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path.

CVSS3: 5.3
EPSS: Средний
debian логотип

CVE-2022-22968

больше 3 лет назад

In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older ...

CVSS3: 5.3
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
debian логотип
CVE-2022-22970

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupp ...

CVSS3: 5.3
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-22971

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2022-22970

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-22970

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.

CVSS3: 5.3
0%
Низкий
около 3 лет назад
redhat логотип
CVE-2022-22971

In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-xjrf-8x4f-43h4

Improper Neutralization of Input During Web Page Generation in Spring Framework

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-wjjr-h4wh-w6vv

Spring Framework Inefficient Regular Expression Complexity

1%
Низкий
больше 3 лет назад
github логотип
GHSA-g5mm-vmx4-3rg7

Improper handling of case sensitivity in Spring Framework

CVSS3: 7.5
23%
Средний
больше 3 лет назад
nvd логотип
CVE-2022-22968

In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property path.

CVSS3: 5.3
23%
Средний
больше 3 лет назад
debian логотип
CVE-2022-22968

In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older ...

CVSS3: 5.3
23%
Средний
больше 3 лет назад

Уязвимостей на страницу


Поделиться