Количество 349
Количество 349
GHSA-xjrf-8x4f-43h4
Improper Neutralization of Input During Web Page Generation in Spring Framework
GHSA-x863-p983-p4f7
In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to unauthorized actions via gadget class deserialization. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
GHSA-x23c-287f-qqv5
Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
GHSA-wxqc-pxw9-g2p8
Spring Framework vulnerable to denial of service
GHSA-wxpp-56q6-5pcg
Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
GHSA-wv88-pf73-x22p
Improper Neutralization of Directives in Dynamically Evaluated Code in Spring Framework
GHSA-wg35-8jpf-2xv3
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.
GHSA-vqgp-pf68-6947
Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48.
GHSA-vp63-rrcm-9mph
Missing XML Validation in Spring Framework
GHSA-v94h-hvhg-mf9h
Spring Framework vulnerable to denial of service
GHSA-rp4p-g69r-438x
Cross-Site Request Forgery in Spring Framework
GHSA-rhcg-rwhx-qj3j
Improper Limitation of a Pathname to a Restricted Directory in Spring Framework
GHSA-r5w3-xv2f-j59q
Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation or unavailability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
GHSA-r4q3-7g4q-x89m
Spring Framework server Web DoS Vulnerability
GHSA-q723-847q-5g8g
Spring Framework Predictable Session ID in WebSocket Module
GHSA-pgf9-h69p-pcgf
Files or Directories Accessible to External Parties in org.springframework:spring-core
GHSA-mq64-j8f9-9gcj
Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
GHSA-hhm4-hwq6-3c6w
Improper Limitation of a Pathname to a Restricted Directory in Spring Framework
GHSA-h3qp-gqrc-q736
A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to craft a link resulting in a 302 redirect to an arbitrary external host via the redirect: prefix. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
GHSA-g6hf-f9cq-q7w7
Cross-Site Request Forgery in Spring Framework
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xjrf-8x4f-43h4 Improper Neutralization of Input During Web Page Generation in Spring Framework | CVSS3: 5.4 | 3% Низкий | около 4 лет назад | |
GHSA-x863-p983-p4f7 In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to unauthorized actions via gadget class deserialization. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | CVSS3: 8.1 | 0% Низкий | около 2 месяцев назад | |
GHSA-x23c-287f-qqv5 Spring MVC and WebFlux applications are vulnerable to Denial of Service (DoS) attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | CVSS3: 7.5 | 0% Низкий | около 2 месяцев назад | |
GHSA-wxqc-pxw9-g2p8 Spring Framework vulnerable to denial of service | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-wxpp-56q6-5pcg Applications which accept user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack if the evaluation of a SpEL expression triggers unbounded cache growth. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | CVSS3: 5.3 | 0% Низкий | около 2 месяцев назад | |
GHSA-wv88-pf73-x22p Improper Neutralization of Directives in Dynamically Evaluated Code in Spring Framework | 12% Средний | около 4 лет назад | ||
GHSA-wg35-8jpf-2xv3 Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources. | CVSS3: 3.1 | 0% Низкий | 3 месяца назад | |
GHSA-vqgp-pf68-6947 Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48. | CVSS3: 4.8 | 0% Низкий | около 2 месяцев назад | |
GHSA-vp63-rrcm-9mph Missing XML Validation in Spring Framework | 5% Низкий | около 4 лет назад | ||
GHSA-v94h-hvhg-mf9h Spring Framework vulnerable to denial of service | CVSS3: 7.5 | 1% Низкий | больше 2 лет назад | |
GHSA-rp4p-g69r-438x Cross-Site Request Forgery in Spring Framework | 26% Средний | около 4 лет назад | ||
GHSA-rhcg-rwhx-qj3j Improper Limitation of a Pathname to a Restricted Directory in Spring Framework | 6% Низкий | около 4 лет назад | ||
GHSA-r5w3-xv2f-j59q Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions are vulnerable to an Algorithmic Denial of Service (DoS). By providing a specially crafted expression, an attacker can trigger excessive resource consumption during evaluation, leading to application degradation or unavailability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | CVSS3: 7.5 | 0% Низкий | около 2 месяцев назад | |
GHSA-r4q3-7g4q-x89m Spring Framework server Web DoS Vulnerability | CVSS3: 7.5 | 1% Низкий | больше 2 лет назад | |
GHSA-q723-847q-5g8g Spring Framework Predictable Session ID in WebSocket Module | CVSS3: 4.8 | 0% Низкий | около 2 месяцев назад | |
GHSA-pgf9-h69p-pcgf Files or Directories Accessible to External Parties in org.springframework:spring-core | CVSS3: 8.6 | 3% Низкий | почти 8 лет назад | |
GHSA-mq64-j8f9-9gcj Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | CVSS3: 5.9 | 0% Низкий | около 2 месяцев назад | |
GHSA-hhm4-hwq6-3c6w Improper Limitation of a Pathname to a Restricted Directory in Spring Framework | 10% Средний | около 4 лет назад | ||
GHSA-h3qp-gqrc-q736 A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to craft a link resulting in a 302 redirect to an arbitrary external host via the redirect: prefix. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | CVSS3: 4.2 | 0% Низкий | около 2 месяцев назад | |
GHSA-g6hf-f9cq-q7w7 Cross-Site Request Forgery in Spring Framework | 90% Критический | около 4 лет назад |
Уязвимостей на страницу