Количество 423
Количество 423
GHSA-pc63-qcmh-9cmg
Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
GHSA-mq64-j8f9-9gcj
Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux
GHSA-m843-fc87-4v2m
Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL expression compiler is active. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
GHSA-j9f9-w8pj-32f8
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
GHSA-j94g-vwjh-xffq
UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
GHSA-j392-mc64-q79h
Applications that build a Content-Disposition header value from untrusted input may be vulnerable to HTTP response splitting when the input is a malicious file name. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
GHSA-hhm4-hwq6-3c6w
Improper Limitation of a Pathname to a Restricted Directory in Spring Framework
GHSA-h3qp-gqrc-q736
Spring Framework Open Redirect in Spring MVC and WebFlux
GHSA-g782-8rcv-55rh
Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
GHSA-g6hf-f9cq-q7w7
Cross-Site Request Forgery in Spring Framework
GHSA-ff7p-jqjm-v66h
Improper Neutralization of Input During Web Page Generation in Spring Framework
GHSA-f93f-g33r-8pcp
Improper Restriction of XML External Entity Reference in Spring Framework
GHSA-f8c6-vfp5-9fpp
A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
GHSA-cqhh-73qg-8434
Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE). Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49
GHSA-cjpg-rgq5-fr37
Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux
GHSA-9qf2-26p9-2q2q
A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.5.RELEASE - 5.2.25.RELEASE
GHSA-9f52-rjqv-25qv
Spring Framework Arbitrary Method Invocation in SpEL Expressions
GHSA-96vf-qc2m-7q49
Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may be vulnerable to a Denial of Service (DoS) attack. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
GHSA-957g-f97v-vppc
Spring Framework Cross-site Scripting via JSP Form Tags
GHSA-8cmm-qj8g-fcp6
Cross-Site Request Forgery in Spring Framework
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-pc63-qcmh-9cmg Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier | CVSS3: 9.8 | 0% Низкий | 23 дня назад | |
GHSA-mq64-j8f9-9gcj Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux | CVSS3: 5.9 | 0% Низкий | 3 месяца назад | |
GHSA-m843-fc87-4v2m Applications that evaluate Spring Expression Language (SpEL) expressions using SimpleEvaluationContext may be vulnerable to a safety guard bypass when the SpEL expression compiler is active. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier | CVSS3: 9.1 | 0% Низкий | 22 дня назад | |
GHSA-j9f9-w8pj-32f8 Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 | CVSS3: 9.8 | 0% Низкий | 23 дня назад | |
GHSA-j94g-vwjh-xffq UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 | CVSS3: 6.1 | 0% Низкий | 23 дня назад | |
GHSA-j392-mc64-q79h Applications that build a Content-Disposition header value from untrusted input may be vulnerable to HTTP response splitting when the input is a malicious file name. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier | CVSS3: 3.7 | 0% Низкий | 22 дня назад | |
GHSA-hhm4-hwq6-3c6w Improper Limitation of a Pathname to a Restricted Directory in Spring Framework | 10% Средний | больше 4 лет назад | ||
GHSA-h3qp-gqrc-q736 Spring Framework Open Redirect in Spring MVC and WebFlux | CVSS3: 4.2 | 0% Низкий | 3 месяца назад | |
GHSA-g782-8rcv-55rh Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier | CVSS3: 7.5 | 0% Низкий | 23 дня назад | |
GHSA-g6hf-f9cq-q7w7 Cross-Site Request Forgery in Spring Framework | 91% Критический | больше 4 лет назад | ||
GHSA-ff7p-jqjm-v66h Improper Neutralization of Input During Web Page Generation in Spring Framework | 7% Низкий | больше 4 лет назад | ||
GHSA-f93f-g33r-8pcp Improper Restriction of XML External Entity Reference in Spring Framework | CVSS3: 8.8 | 2% Низкий | больше 4 лет назад | |
GHSA-f8c6-vfp5-9fpp A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier | CVSS3: 6.1 | 0% Низкий | 23 дня назад | |
GHSA-cqhh-73qg-8434 Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Events (SSE). Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 | CVSS3: 9.8 | 0% Низкий | 22 дня назад | |
GHSA-cjpg-rgq5-fr37 Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
GHSA-9qf2-26p9-2q2q A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.5.RELEASE - 5.2.25.RELEASE | CVSS3: 9.8 | 0% Низкий | 23 дня назад | |
GHSA-9f52-rjqv-25qv Spring Framework Arbitrary Method Invocation in SpEL Expressions | CVSS3: 3.7 | 0% Низкий | 3 месяца назад | |
GHSA-96vf-qc2m-7q49 Spring Framework applications that use Spring's data binding infrastructure to apply user-supplied property paths onto a target object may be vulnerable to a Denial of Service (DoS) attack. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier | CVSS3: 7.5 | 0% Низкий | 22 дня назад | |
GHSA-957g-f97v-vppc Spring Framework Cross-site Scripting via JSP Form Tags | CVSS3: 5.9 | 0% Низкий | 3 месяца назад | |
GHSA-8cmm-qj8g-fcp6 Cross-Site Request Forgery in Spring Framework | 91% Критический | больше 4 лет назад |
Уязвимостей на страницу