Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 349

Количество 349

github логотип

GHSA-ff7p-jqjm-v66h

около 4 лет назад

Improper Neutralization of Input During Web Page Generation in Spring Framework

EPSS: Низкий
github логотип

GHSA-f93f-g33r-8pcp

около 4 лет назад

Improper Restriction of XML External Entity Reference in Spring Framework

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-cjpg-rgq5-fr37

около 2 месяцев назад

Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-9f52-rjqv-25qv

около 2 месяцев назад

A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-957g-f97v-vppc

около 2 месяцев назад

Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScript code injection, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-8cmm-qj8g-fcp6

около 4 лет назад

Cross-Site Request Forgery in Spring Framework

EPSS: Критический
github логотип

GHSA-83f7-v6px-pp3h

около 2 месяцев назад

Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-7phw-cxx7-q9vq

больше 3 лет назад

Spring Framework is vulnerable to security bypass via mvcRequestMatcher pattern mismatch

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-7m2p-62gw-p8qq

около 2 месяцев назад

Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18.

CVSS3: 4.2
EPSS: Низкий
github логотип

GHSA-775g-4xr8-78h8

около 2 месяцев назад

An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected versions: Spring Framework 5.3.0 through 5.3.48.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-72pg-x5f8-j25j

около 2 месяцев назад

Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-6v7w-535j-rq5m

почти 8 лет назад

Pivotal Spring Framework DoS Attack with XML Input

CVSS3: 5.5
EPSS: Низкий
github логотип

GHSA-6p4f-wcwh-5vvm

3 месяца назад

Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-6hcq-hmm3-jj3c

4 месяца назад

Spring MVC and WebFlux has Server Sent Event stream corruption

CVSS3: 2.6
EPSS: Низкий
github логотип

GHSA-659m-px2c-25wj

около 2 месяцев назад

Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(String pattern, String path), matchStart(String pattern, String path), extractUriTemplateVariables(String pattern, String path). Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 3.7
EPSS: Низкий
github логотип

GHSA-5843-p793-ghmm

3 месяца назад

Spring Framework DoS with Multipart Temp Files in WebFlux

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-564r-hj7v-mcr5

больше 3 лет назад

Spring Framework vulnerable to denial of service via specially crafted SpEL expression

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-558x-2xjg-6232

больше 4 лет назад

Allocation of Resources Without Limits or Throttling in Spring Framework

CVSS3: 6.5
EPSS: Средний
github логотип

GHSA-4wrc-f8pq-fpqp

около 4 лет назад

Pivotal Spring Framework contains unsafe Java deserialization methods

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-4hfh-6x8g-gwpp

около 2 месяцев назад

A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerable to an escalation attack exchanging a known session ID for that of an authenticated user. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 4.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-ff7p-jqjm-v66h

Improper Neutralization of Input During Web Page Generation in Spring Framework

3%
Низкий
около 4 лет назад
github логотип
GHSA-f93f-g33r-8pcp

Improper Restriction of XML External Entity Reference in Spring Framework

CVSS3: 8.8
2%
Низкий
около 4 лет назад
github логотип
GHSA-cjpg-rgq5-fr37

Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 5.3
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-9f52-rjqv-25qv

A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 3.7
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-957g-f97v-vppc

Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScript code injection, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 5.9
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-8cmm-qj8g-fcp6

Cross-Site Request Forgery in Spring Framework

91%
Критический
около 4 лет назад
github логотип
GHSA-83f7-v6px-pp3h

Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 5.9
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-7phw-cxx7-q9vq

Spring Framework is vulnerable to security bypass via mvcRequestMatcher pattern mismatch

CVSS3: 9.1
4%
Низкий
больше 3 лет назад
github логотип
GHSA-7m2p-62gw-p8qq

Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18.

CVSS3: 4.2
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-775g-4xr8-78h8

An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected versions: Spring Framework 5.3.0 through 5.3.48.

CVSS3: 7.5
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-72pg-x5f8-j25j

Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 5.9
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-6v7w-535j-rq5m

Pivotal Spring Framework DoS Attack with XML Input

CVSS3: 5.5
3%
Низкий
почти 8 лет назад
github логотип
GHSA-6p4f-wcwh-5vvm

Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources

CVSS3: 5.3
0%
Низкий
3 месяца назад
github логотип
GHSA-6hcq-hmm3-jj3c

Spring MVC and WebFlux has Server Sent Event stream corruption

CVSS3: 2.6
0%
Низкий
4 месяца назад
github логотип
GHSA-659m-px2c-25wj

Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(String pattern, String path), matchStart(String pattern, String path), extractUriTemplateVariables(String pattern, String path). Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 3.7
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-5843-p793-ghmm

Spring Framework DoS with Multipart Temp Files in WebFlux

CVSS3: 6.5
0%
Низкий
3 месяца назад
github логотип
GHSA-564r-hj7v-mcr5

Spring Framework vulnerable to denial of service via specially crafted SpEL expression

CVSS3: 6.5
1%
Низкий
больше 3 лет назад
github логотип
GHSA-558x-2xjg-6232

Allocation of Resources Without Limits or Throttling in Spring Framework

CVSS3: 6.5
36%
Средний
больше 4 лет назад
github логотип
GHSA-4wrc-f8pq-fpqp

Pivotal Spring Framework contains unsafe Java deserialization methods

CVSS3: 9.8
32%
Средний
около 4 лет назад
github логотип
GHSA-4hfh-6x8g-gwpp

A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerable to an escalation attack exchanging a known session ID for that of an authenticated user. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

CVSS3: 4.2
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу