Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 349

Количество 349

github логотип

GHSA-xjrf-8x4f-43h4

около 4 лет назад

Improper Neutralization of Input During Web Page Generation in Spring Framework

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-x863-p983-p4f7

около 2 месяцев назад

In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to unauthorized actions via gadget class deserialization. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-x23c-287f-qqv5

около 2 месяцев назад

Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-wxqc-pxw9-g2p8

больше 3 лет назад

Spring Framework vulnerable to denial of service

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-wxpp-56q6-5pcg

около 2 месяцев назад

Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-wv88-pf73-x22p

около 4 лет назад

Improper Neutralization of Directives in Dynamically Evaluated Code in Spring Framework

EPSS: Средний
github логотип

GHSA-wg35-8jpf-2xv3

3 месяца назад

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-vqgp-pf68-6947

около 2 месяцев назад

Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48.

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-vp63-rrcm-9mph

около 4 лет назад

Missing XML Validation in Spring Framework

EPSS: Низкий
github логотип

GHSA-v94h-hvhg-mf9h

больше 2 лет назад

Spring Framework vulnerable to denial of service

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-rp4p-g69r-438x

около 4 лет назад

Cross-Site Request Forgery in Spring Framework

EPSS: Средний
github логотип

GHSA-rhcg-rwhx-qj3j

около 4 лет назад

Improper Limitation of a Pathname to a Restricted Directory in Spring Framework

EPSS: Низкий
github логотип

GHSA-r5w3-xv2f-j59q

около 2 месяцев назад

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation or unavailability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-r4q3-7g4q-x89m

больше 2 лет назад

Spring Framework server Web DoS Vulnerability

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-q723-847q-5g8g

около 2 месяцев назад

Spring Framework Predictable Session ID in WebSocket Module

CVSS3: 4.8
EPSS: Низкий
github логотип

GHSA-pgf9-h69p-pcgf

почти 8 лет назад

Files or Directories Accessible to External Parties in org.springframework:spring-core

CVSS3: 8.6
EPSS: Низкий
github логотип

GHSA-mq64-j8f9-9gcj

около 2 месяцев назад

Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-hhm4-hwq6-3c6w

около 4 лет назад

Improper Limitation of a Pathname to a Restricted Directory in Spring Framework

EPSS: Средний
github логотип

GHSA-h3qp-gqrc-q736

около 2 месяцев назад

A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to craft a link resulting in a 302 redirect to an arbitrary external host via the redirect: prefix. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-g6hf-f9cq-q7w7

около 4 лет назад

Cross-Site Request Forgery in Spring Framework

EPSS: Критический

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-xjrf-8x4f-43h4

Improper Neutralization of Input During Web Page Generation in Spring Framework

CVSS3: 5.4
3%
Низкий
около 4 лет назад
github логотип
GHSA-x863-p983-p4f7

In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to unauthorized actions via gadget class deserialization. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 8.1
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-x23c-287f-qqv5

Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-wxqc-pxw9-g2p8

Spring Framework vulnerable to denial of service

CVSS3: 7.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-wxpp-56q6-5pcg

Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-wv88-pf73-x22p

Improper Neutralization of Directives in Dynamically Evaluated Code in Spring Framework

12%
Средний
около 4 лет назад
github логотип
GHSA-wg35-8jpf-2xv3

Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.

CVSS3: 3.1
0%
Низкий
3 месяца назад
github логотип
GHSA-vqgp-pf68-6947

Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48.

CVSS3: 4.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-vp63-rrcm-9mph

Missing XML Validation in Spring Framework

5%
Низкий
около 4 лет назад
github логотип
GHSA-v94h-hvhg-mf9h

Spring Framework vulnerable to denial of service

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-rp4p-g69r-438x

Cross-Site Request Forgery in Spring Framework

26%
Средний
около 4 лет назад
github логотип
GHSA-rhcg-rwhx-qj3j

Improper Limitation of a Pathname to a Restricted Directory in Spring Framework

6%
Низкий
около 4 лет назад
github логотип
GHSA-r5w3-xv2f-j59q

Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation or unavailability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-r4q3-7g4q-x89m

Spring Framework server Web DoS Vulnerability

CVSS3: 7.5
1%
Низкий
больше 2 лет назад
github логотип
GHSA-q723-847q-5g8g

Spring Framework Predictable Session ID in WebSocket Module

CVSS3: 4.8
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-pgf9-h69p-pcgf

Files or Directories Accessible to External Parties in org.springframework:spring-core

CVSS3: 8.6
3%
Низкий
почти 8 лет назад
github логотип
GHSA-mq64-j8f9-9gcj

Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 5.9
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-hhm4-hwq6-3c6w

Improper Limitation of a Pathname to a Restricted Directory in Spring Framework

10%
Средний
около 4 лет назад
github логотип
GHSA-h3qp-gqrc-q736

A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to craft a link resulting in a 302 redirect to an arbitrary external host via the redirect: prefix. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 4.2
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-g6hf-f9cq-q7w7

Cross-Site Request Forgery in Spring Framework

90%
Критический
около 4 лет назад

Уязвимостей на страницу