Количество 349
Количество 349
GHSA-ff7p-jqjm-v66h
Improper Neutralization of Input During Web Page Generation in Spring Framework
GHSA-f93f-g33r-8pcp
Improper Restriction of XML External Entity Reference in Spring Framework
GHSA-cjpg-rgq5-fr37
Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
GHSA-9f52-rjqv-25qv
A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
GHSA-957g-f97v-vppc
Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScript code injection, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
GHSA-8cmm-qj8g-fcp6
Cross-Site Request Forgery in Spring Framework
GHSA-83f7-v6px-pp3h
Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
GHSA-7phw-cxx7-q9vq
Spring Framework is vulnerable to security bypass via mvcRequestMatcher pattern mismatch
GHSA-7m2p-62gw-p8qq
Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18.
GHSA-775g-4xr8-78h8
An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected versions: Spring Framework 5.3.0 through 5.3.48.
GHSA-72pg-x5f8-j25j
Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
GHSA-6v7w-535j-rq5m
Pivotal Spring Framework DoS Attack with XML Input
GHSA-6p4f-wcwh-5vvm
Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources
GHSA-6hcq-hmm3-jj3c
Spring MVC and WebFlux has Server Sent Event stream corruption
GHSA-659m-px2c-25wj
Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(String pattern, String path), matchStart(String pattern, String path), extractUriTemplateVariables(String pattern, String path). Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
GHSA-5843-p793-ghmm
Spring Framework DoS with Multipart Temp Files in WebFlux
GHSA-564r-hj7v-mcr5
Spring Framework vulnerable to denial of service via specially crafted SpEL expression
GHSA-558x-2xjg-6232
Allocation of Resources Without Limits or Throttling in Spring Framework
GHSA-4wrc-f8pq-fpqp
Pivotal Spring Framework contains unsafe Java deserialization methods
GHSA-4hfh-6x8g-gwpp
A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerable to an escalation attack exchanging a known session ID for that of an authenticated user. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-ff7p-jqjm-v66h Improper Neutralization of Input During Web Page Generation in Spring Framework | 3% Низкий | около 4 лет назад | ||
GHSA-f93f-g33r-8pcp Improper Restriction of XML External Entity Reference in Spring Framework | CVSS3: 8.8 | 2% Низкий | около 4 лет назад | |
GHSA-cjpg-rgq5-fr37 Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | CVSS3: 5.3 | 0% Низкий | около 2 месяцев назад | |
GHSA-9f52-rjqv-25qv A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker to invoke unintended application logic. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | CVSS3: 3.7 | 0% Низкий | около 2 месяцев назад | |
GHSA-957g-f97v-vppc Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScript code injection, potentially resulting in a cross-site scripting (XSS) vulnerability. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | CVSS3: 5.9 | 0% Низкий | около 2 месяцев назад | |
GHSA-8cmm-qj8g-fcp6 Cross-Site Request Forgery in Spring Framework | 91% Критический | около 4 лет назад | ||
GHSA-83f7-v6px-pp3h Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | CVSS3: 5.9 | 0% Низкий | около 2 месяцев назад | |
GHSA-7phw-cxx7-q9vq Spring Framework is vulnerable to security bypass via mvcRequestMatcher pattern mismatch | CVSS3: 9.1 | 4% Низкий | больше 3 лет назад | |
GHSA-7m2p-62gw-p8qq Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18. | CVSS3: 4.2 | 0% Низкий | около 2 месяцев назад | |
GHSA-775g-4xr8-78h8 An integer overflow vulnerability exists in the evaluation logic of the Spring Expression Language (SpEL). An attacker can exploit this by supplying a specially crafted SpEL expression that triggers excessive resource consumption, resulting in a Denial of Service (DoS). Affected versions: Spring Framework 5.3.0 through 5.3.48. | CVSS3: 7.5 | 0% Низкий | около 2 месяцев назад | |
GHSA-72pg-x5f8-j25j Spring MVC and WebFlux applications are vulnerable to Path Traversal attacks when resolving static resources. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | CVSS3: 5.9 | 0% Низкий | около 2 месяцев назад | |
GHSA-6v7w-535j-rq5m Pivotal Spring Framework DoS Attack with XML Input | CVSS3: 5.5 | 3% Низкий | почти 8 лет назад | |
GHSA-6p4f-wcwh-5vvm Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
GHSA-6hcq-hmm3-jj3c Spring MVC and WebFlux has Server Sent Event stream corruption | CVSS3: 2.6 | 0% Низкий | 4 месяца назад | |
GHSA-659m-px2c-25wj Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(String pattern, String path), matchStart(String pattern, String path), extractUriTemplateVariables(String pattern, String path). Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | CVSS3: 3.7 | 0% Низкий | около 2 месяцев назад | |
GHSA-5843-p793-ghmm Spring Framework DoS with Multipart Temp Files in WebFlux | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
GHSA-564r-hj7v-mcr5 Spring Framework vulnerable to denial of service via specially crafted SpEL expression | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
GHSA-558x-2xjg-6232 Allocation of Resources Without Limits or Throttling in Spring Framework | CVSS3: 6.5 | 36% Средний | больше 4 лет назад | |
GHSA-4wrc-f8pq-fpqp Pivotal Spring Framework contains unsafe Java deserialization methods | CVSS3: 9.8 | 32% Средний | около 4 лет назад | |
GHSA-4hfh-6x8g-gwpp A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerable to an escalation attack exchanging a known session ID for that of an authenticated user. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48. | CVSS3: 4.2 | 0% Низкий | около 2 месяцев назад |
Уязвимостей на страницу