Логотип exploitDog
product: "spring_framework"
Консоль
Логотип exploitDog

exploitDog

product: "spring_framework"
Spring Framework

Spring Frameworkуниверсальный фреймворк с открытым исходным кодом для Java-платформы.

Релизный цикл, информация об уязвимостях

Продукт: Spring Framework
Вендор: VMware

График релизов

6.27.020242025202620272028

Недавние уязвимости Spring Framework

Количество 241

redhat логотип

CVE-2022-22965

почти 4 года назад

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

CVSS3: 8.1
EPSS: Критический
redhat логотип

CVE-2022-22950

почти 4 года назад

n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-6gf2-pvqw-37ph

около 4 лет назад

Log entry injection in Spring Framework

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-22060

около 4 лет назад

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-22060

около 4 лет назад

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-22060

около 4 лет назад

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2021-22060

около 4 лет назад

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-22096

больше 4 лет назад

In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-22096

больше 4 лет назад

In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-22096

больше 4 лет назад

In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2022-22965

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

CVSS3: 8.1
94%
Критический
почти 4 года назад
redhat логотип
CVE-2022-22950

n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.

CVSS3: 7.5
4%
Низкий
почти 4 года назад
github логотип
GHSA-6gf2-pvqw-37ph

Log entry injection in Spring Framework

CVSS3: 4.3
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-22060

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
debian логотип
CVE-2021-22060

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older ...

CVSS3: 4.3
0%
Низкий
около 4 лет назад
ubuntu логотип
CVE-2021-22060

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
redhat логотип
CVE-2021-22060

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.

CVSS3: 4.3
0%
Низкий
около 4 лет назад
nvd логотип
CVE-2021-22096

In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
debian логотип
CVE-2021-22096

In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older ...

CVSS3: 4.3
0%
Низкий
больше 4 лет назад
ubuntu логотип
CVE-2021-22096

In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.

CVSS3: 4.3
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу


Поделиться