Логотип exploitDog
product: "spring_framework"
Консоль
Логотип exploitDog

exploitDog

product: "spring_framework"

Количество 236

Количество 236

debian логотип

CVE-2022-22968

около 3 лет назад

In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older ...

CVSS3: 5.3
EPSS: Средний
github логотип

GHSA-rfmp-97jj-h8m6

около 3 лет назад

Improper Output Neutralization for Logs in Spring Framework

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2021-22096

больше 3 лет назад

In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2021-22096

больше 3 лет назад

In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-22096

больше 3 лет назад

In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-22096

больше 3 лет назад

In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older ...

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-3rmv-2pg5-xvqj

больше 6 лет назад

Spring Framework has Improperly Implemented Security Check for Standard

CVSS3: 9.8
EPSS: Средний
ubuntu логотип

CVE-2018-1275

около 7 лет назад

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for CVE-2018-1270 in the 4.3.x branch of the Spring Framework.

CVSS3: 9.8
EPSS: Средний
redhat логотип

CVE-2018-1275

около 7 лет назад

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for CVE-2018-1270 in the 4.3.x branch of the Spring Framework.

CVSS3: 9.8
EPSS: Средний
nvd логотип

CVE-2018-1275

около 7 лет назад

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for CVE-2018-1270 in the 4.3.x branch of the Spring Framework.

CVSS3: 9.8
EPSS: Средний
debian логотип

CVE-2018-1275

около 7 лет назад

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior t ...

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-4487-x383-qpph

больше 6 лет назад

Possible privilege escalation in org.springframework:spring-core

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2018-1272

около 7 лет назад

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote client, and then uses that input to make a multipart request to another server (server B), it can be exposed to an attack, where an extra multipart is inserted in the content of the request from server A, causing server B to use the wrong value for a part it expects. This could to lead privilege escalation, for example, if the part content represents a username or user roles.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2018-1272

около 7 лет назад

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote client, and then uses that input to make a multipart request to another server (server B), it can be exposed to an attack, where an extra multipart is inserted in the content of the request from server A, causing server B to use the wrong value for a part it expects. This could to lead privilege escalation, for example, if the part content represents a username or user roles.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2018-1272

около 7 лет назад

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote client, and then uses that input to make a multipart request to another server (server B), it can be exposed to an attack, where an extra multipart is inserted in the content of the request from server A, causing server B to use the wrong value for a part it expects. This could to lead privilege escalation, for example, if the part content represents a username or user roles.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2018-1272

около 7 лет назад

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior t ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-p5hg-3xm3-gcjg

больше 6 лет назад

Spring Framework allows applications to expose STOMP over WebSocket endpoints

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-f26x-pr96-vw86

больше 6 лет назад

Moderate severity vulnerability that affects org.springframework:spring-core

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-7pm4-g2qj-j85x

больше 5 лет назад

CSRF attack via CORS preflight requests with Spring MVC or Spring WebFlux

CVSS3: 5.3
EPSS: Низкий
ubuntu логотип

CVE-2020-5397

больше 5 лет назад

Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail authentication. However a notable exception to this are Chrome based browsers when using client certificates for authentication since Chrome sends TLS client certificates in CORS preflight requests in violation of spec requirements. No HTTP body can be sent or received as a result of this attack.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
debian логотип
CVE-2022-22968

In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older ...

CVSS3: 5.3
23%
Средний
около 3 лет назад
github логотип
GHSA-rfmp-97jj-h8m6

Improper Output Neutralization for Logs in Spring Framework

CVSS3: 4.3
0%
Низкий
около 3 лет назад
ubuntu логотип
CVE-2021-22096

In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
redhat логотип
CVE-2021-22096

In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2021-22096

In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2021-22096

In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older ...

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
github логотип
GHSA-3rmv-2pg5-xvqj

Spring Framework has Improperly Implemented Security Check for Standard

CVSS3: 9.8
32%
Средний
больше 6 лет назад
ubuntu логотип
CVE-2018-1275

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for CVE-2018-1270 in the 4.3.x branch of the Spring Framework.

CVSS3: 9.8
32%
Средний
около 7 лет назад
redhat логотип
CVE-2018-1275

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for CVE-2018-1270 in the 4.3.x branch of the Spring Framework.

CVSS3: 9.8
32%
Средний
около 7 лет назад
nvd логотип
CVE-2018-1275

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for CVE-2018-1270 in the 4.3.x branch of the Spring Framework.

CVSS3: 9.8
32%
Средний
около 7 лет назад
debian логотип
CVE-2018-1275

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior t ...

CVSS3: 9.8
32%
Средний
около 7 лет назад
github логотип
GHSA-4487-x383-qpph

Possible privilege escalation in org.springframework:spring-core

CVSS3: 7.5
2%
Низкий
больше 6 лет назад
ubuntu логотип
CVE-2018-1272

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote client, and then uses that input to make a multipart request to another server (server B), it can be exposed to an attack, where an extra multipart is inserted in the content of the request from server A, causing server B to use the wrong value for a part it expects. This could to lead privilege escalation, for example, if the part content represents a username or user roles.

CVSS3: 7.5
2%
Низкий
около 7 лет назад
redhat логотип
CVE-2018-1272

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote client, and then uses that input to make a multipart request to another server (server B), it can be exposed to an attack, where an extra multipart is inserted in the content of the request from server A, causing server B to use the wrong value for a part it expects. This could to lead privilege escalation, for example, if the part content represents a username or user roles.

CVSS3: 5.3
2%
Низкий
около 7 лет назад
nvd логотип
CVE-2018-1272

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote client, and then uses that input to make a multipart request to another server (server B), it can be exposed to an attack, where an extra multipart is inserted in the content of the request from server A, causing server B to use the wrong value for a part it expects. This could to lead privilege escalation, for example, if the part content represents a username or user roles.

CVSS3: 7.5
2%
Низкий
около 7 лет назад
debian логотип
CVE-2018-1272

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior t ...

CVSS3: 7.5
2%
Низкий
около 7 лет назад
github логотип
GHSA-p5hg-3xm3-gcjg

Spring Framework allows applications to expose STOMP over WebSocket endpoints

CVSS3: 9.8
89%
Высокий
больше 6 лет назад
github логотип
GHSA-f26x-pr96-vw86

Moderate severity vulnerability that affects org.springframework:spring-core

CVSS3: 5.9
8%
Низкий
больше 6 лет назад
github логотип
GHSA-7pm4-g2qj-j85x

CSRF attack via CORS preflight requests with Spring MVC or Spring WebFlux

CVSS3: 5.3
1%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2020-5397

Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail authentication. However a notable exception to this are Chrome based browsers when using client certificates for authentication since Chrome sends TLS client certificates in CORS preflight requests in violation of spec requirements. No HTTP body can be sent or received as a result of this attack.

CVSS3: 5.3
1%
Низкий
больше 5 лет назад

Уязвимостей на страницу