Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 423

Количество 423

redhat логотип

CVE-2018-1271

больше 8 лет назад

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a request using a specially crafted URL that can lead a directory traversal attack.

CVSS3: 6.5
EPSS: Средний
nvd логотип

CVE-2018-1271

больше 8 лет назад

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a request using a specially crafted URL that can lead a directory traversal attack.

CVSS3: 5.9
EPSS: Средний
debian логотип

CVE-2018-1271

больше 8 лет назад

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior t ...

CVSS3: 5.9
EPSS: Средний
github логотип

GHSA-rcpf-vj53-7h2m

почти 8 лет назад

Denial of Service in org.springframework:spring-core

CVSS3: 6.5
EPSS: Низкий
ubuntu логотип

CVE-2018-1257

больше 8 лет назад

Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.

CVSS3: 6.5
EPSS: Низкий
redhat логотип

CVE-2018-1257

больше 8 лет назад

Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.

CVSS3: 4.8
EPSS: Низкий
nvd логотип

CVE-2018-1257

больше 8 лет назад

Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.

CVSS3: 6.5
EPSS: Низкий
debian логотип

CVE-2018-1257

больше 8 лет назад

Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior ...

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-gfwj-fwqj-fp3v

больше 4 лет назад

Improper Privilege Management in Spring Framework

CVSS3: 7.8
EPSS: Низкий
github логотип

GHSA-9gcm-f4x3-8jpw

почти 8 лет назад

Spring Framework Cross Site Tracing (XST)

CVSS3: 5.9
EPSS: Низкий
ubuntu логотип

CVE-2021-22118

больше 5 лет назад

In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.

CVSS3: 7.8
EPSS: Низкий
redhat логотип

CVE-2021-22118

больше 5 лет назад

In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.

CVSS3: 7.1
EPSS: Низкий
nvd логотип

CVE-2021-22118

больше 5 лет назад

In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.

CVSS3: 7.8
EPSS: Низкий
debian логотип

CVE-2021-22118

больше 5 лет назад

In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x ...

CVSS3: 7.8
EPSS: Низкий
ubuntu логотип

CVE-2018-11039

около 8 лет назад

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.

CVSS3: 5.9
EPSS: Низкий
redhat логотип

CVE-2018-11039

больше 8 лет назад

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2018-11039

около 8 лет назад

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2018-11039

около 8 лет назад

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior ...

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-8wx2-9q48-vm9r

больше 6 лет назад

RFD attack via Content-Disposition header sourced from request input by Spring MVC or Spring WebFlux Application

CVSS3: 7.5
EPSS: Высокий
ubuntu логотип

CVE-2020-5398

больше 6 лет назад

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.

CVSS3: 7.5
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2018-1271

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a request using a specially crafted URL that can lead a directory traversal attack.

CVSS3: 6.5
34%
Средний
больше 8 лет назад
nvd логотип
CVE-2018-1271

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a request using a specially crafted URL that can lead a directory traversal attack.

CVSS3: 5.9
34%
Средний
больше 8 лет назад
debian логотип
CVE-2018-1271

Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior t ...

CVSS3: 5.9
34%
Средний
больше 8 лет назад
github логотип
GHSA-rcpf-vj53-7h2m

Denial of Service in org.springframework:spring-core

CVSS3: 6.5
3%
Низкий
почти 8 лет назад
ubuntu логотип
CVE-2018-1257

Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.

CVSS3: 6.5
3%
Низкий
больше 8 лет назад
redhat логотип
CVE-2018-1257

Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.

CVSS3: 4.8
3%
Низкий
больше 8 лет назад
nvd логотип
CVE-2018-1257

Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.

CVSS3: 6.5
3%
Низкий
больше 8 лет назад
debian логотип
CVE-2018-1257

Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior ...

CVSS3: 6.5
3%
Низкий
больше 8 лет назад
github логотип
GHSA-gfwj-fwqj-fp3v

Improper Privilege Management in Spring Framework

CVSS3: 7.8
0%
Низкий
больше 4 лет назад
github логотип
GHSA-9gcm-f4x3-8jpw

Spring Framework Cross Site Tracing (XST)

CVSS3: 5.9
3%
Низкий
почти 8 лет назад
ubuntu логотип
CVE-2021-22118

In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.

CVSS3: 7.8
0%
Низкий
больше 5 лет назад
redhat логотип
CVE-2021-22118

In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.

CVSS3: 7.1
0%
Низкий
больше 5 лет назад
nvd логотип
CVE-2021-22118

In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.

CVSS3: 7.8
0%
Низкий
больше 5 лет назад
debian логотип
CVE-2021-22118

In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x ...

CVSS3: 7.8
0%
Низкий
больше 5 лет назад
ubuntu логотип
CVE-2018-11039

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.

CVSS3: 5.9
3%
Низкий
около 8 лет назад
redhat логотип
CVE-2018-11039

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.

CVSS3: 3.7
3%
Низкий
больше 8 лет назад
nvd логотип
CVE-2018-11039

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tracing) attack.

CVSS3: 5.9
3%
Низкий
около 8 лет назад
debian логотип
CVE-2018-11039

Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior ...

CVSS3: 5.9
3%
Низкий
около 8 лет назад
github логотип
GHSA-8wx2-9q48-vm9r

RFD attack via Content-Disposition header sourced from request input by Spring MVC or Spring WebFlux Application

CVSS3: 7.5
88%
Высокий
больше 6 лет назад
ubuntu логотип
CVE-2020-5398

In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.

CVSS3: 7.5
88%
Высокий
больше 6 лет назад

Уязвимостей на страницу