Количество 423
Количество 423
GHSA-xjrf-8x4f-43h4
Improper Neutralization of Input During Web Page Generation in Spring Framework
GHSA-x863-p983-p4f7
Spring Framework Unsafe Deserialization via Jackson JMS Converters
GHSA-x23c-287f-qqv5
Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux
GHSA-wxqc-pxw9-g2p8
Spring Framework vulnerable to denial of service
GHSA-wxpp-56q6-5pcg
Spring Framework Denial of Service via Unbounded Cache in SpEL
GHSA-wv88-pf73-x22p
Improper Neutralization of Directives in Dynamically Evaluated Code in Spring Framework
GHSA-wg35-8jpf-2xv3
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.
GHSA-vw3r-pj6g-mjg8
A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
GHSA-vqgp-pf68-6947
Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL
GHSA-vp63-rrcm-9mph
Missing XML Validation in Spring Framework
GHSA-v94h-hvhg-mf9h
Spring Framework vulnerable to denial of service
GHSA-rxw8-5hfh-3jfv
A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.0.RELEASE - 5.2.25.RELEASE
GHSA-rp4p-g69r-438x
Cross-Site Request Forgery in Spring Framework
GHSA-rhcg-rwhx-qj3j
Improper Limitation of a Pathname to a Restricted Directory in Spring Framework
GHSA-r5w3-xv2f-j59q
Spring Framework Algorithmic Denial of Service via SpEL Expressions
GHSA-r4q3-7g4q-x89m
Spring Framework server Web DoS Vulnerability
GHSA-q723-847q-5g8g
Spring Framework Predictable Session ID in WebSocket Module
GHSA-q49m-fm49-9mmx
The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28
GHSA-pppg-c2f5-276v
Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a controller returns a view name derived from untrusted input and FreeMarker is configured to resolve templates through SpringTemplateLoader. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
GHSA-pgf9-h69p-pcgf
Files or Directories Accessible to External Parties in org.springframework:spring-core
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xjrf-8x4f-43h4 Improper Neutralization of Input During Web Page Generation in Spring Framework | CVSS3: 5.4 | 2% Низкий | больше 4 лет назад | |
GHSA-x863-p983-p4f7 Spring Framework Unsafe Deserialization via Jackson JMS Converters | CVSS3: 8.1 | 0% Низкий | 3 месяца назад | |
GHSA-x23c-287f-qqv5 Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
GHSA-wxqc-pxw9-g2p8 Spring Framework vulnerable to denial of service | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-wxpp-56q6-5pcg Spring Framework Denial of Service via Unbounded Cache in SpEL | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
GHSA-wv88-pf73-x22p Improper Neutralization of Directives in Dynamically Evaluated Code in Spring Framework | 12% Средний | больше 4 лет назад | ||
GHSA-wg35-8jpf-2xv3 Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. | CVSS3: 3.1 | 0% Низкий | 5 месяцев назад | |
GHSA-vw3r-pj6g-mjg8 A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier | CVSS3: 7.5 | 0% Низкий | 23 дня назад | |
GHSA-vqgp-pf68-6947 Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL | CVSS3: 4.8 | 0% Низкий | 3 месяца назад | |
GHSA-vp63-rrcm-9mph Missing XML Validation in Spring Framework | 5% Низкий | больше 4 лет назад | ||
GHSA-v94h-hvhg-mf9h Spring Framework vulnerable to denial of service | CVSS3: 7.5 | 1% Низкий | почти 3 года назад | |
GHSA-rxw8-5hfh-3jfv A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.0.RELEASE - 5.2.25.RELEASE | CVSS3: 7.5 | 0% Низкий | 23 дня назад | |
GHSA-rp4p-g69r-438x Cross-Site Request Forgery in Spring Framework | 26% Средний | больше 4 лет назад | ||
GHSA-rhcg-rwhx-qj3j Improper Limitation of a Pathname to a Restricted Directory in Spring Framework | 6% Низкий | больше 4 лет назад | ||
GHSA-r5w3-xv2f-j59q Spring Framework Algorithmic Denial of Service via SpEL Expressions | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
GHSA-r4q3-7g4q-x89m Spring Framework server Web DoS Vulnerability | CVSS3: 7.5 | 1% Низкий | больше 2 лет назад | |
GHSA-q723-847q-5g8g Spring Framework Predictable Session ID in WebSocket Module | CVSS3: 4.8 | 0% Низкий | 3 месяца назад | |
GHSA-q49m-fm49-9mmx The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 | CVSS3: 7.5 | 0% Низкий | 23 дня назад | |
GHSA-pppg-c2f5-276v Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a controller returns a view name derived from untrusted input and FreeMarker is configured to resolve templates through SpringTemplateLoader. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier | CVSS3: 4.3 | 0% Низкий | 22 дня назад | |
GHSA-pgf9-h69p-pcgf Files or Directories Accessible to External Parties in org.springframework:spring-core | CVSS3: 8.6 | 3% Низкий | почти 8 лет назад |
Уязвимостей на страницу