Количество 423
Количество 423
GHSA-83f7-v6px-pp3h
Spring Framework Denial of Service via Multipart Requests in WebFlux
GHSA-7phw-cxx7-q9vq
Spring Framework is vulnerable to security bypass via mvcRequestMatcher pattern mismatch
GHSA-7p67-m4j8-h4vx
A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
GHSA-7m2p-62gw-p8qq
Spring Framework Server-Side Request Forgery via UriComponentsBuilder
GHSA-775g-4xr8-78h8
Spring Framework Denial of Service via Integer Overflow in SpEL Expressions
GHSA-72pg-x5f8-j25j
Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux
GHSA-6v7w-535j-rq5m
Pivotal Spring Framework DoS Attack with XML Input
GHSA-6p4f-wcwh-5vvm
Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources
GHSA-6hcq-hmm3-jj3c
Spring MVC and WebFlux has Server Sent Event stream corruption
GHSA-659m-px2c-25wj
Spring Framework Denial of Service via AntPathMatcher
GHSA-5843-p793-ghmm
Spring Framework DoS with Multipart Temp Files in WebFlux
GHSA-564r-hj7v-mcr5
Spring Framework vulnerable to denial of service via specially crafted SpEL expression
GHSA-558x-2xjg-6232
Allocation of Resources Without Limits or Throttling in Spring Framework
GHSA-549f-4rpc-3rw9
Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping enabled and then render field errors using the no-argument Errors.getFieldErrors() or Errors.getFieldError() accessors are vulnerable to arbitrary HTML/JavaScript code injection, potentially resulting in a reflected cross-site scripting (XSS) vulnerability. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
GHSA-53cv-4frm-9p27
A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
GHSA-4wrc-f8pq-fpqp
Pivotal Spring Framework contains unsafe Java deserialization methods
GHSA-4hfh-6x8g-gwpp
Spring Framework Escalation via Session Fixation in WebFlux
GHSA-4gc7-5j7h-4qph
Spring Framework DataBinder Case Sensitive Match Exception
GHSA-4773-3jfm-qmx3
Spring Framework Improper Path Limitation with Script View Templates
GHSA-45vg-2v73-vm62
Moderate severity vulnerability that affects org.springframework:spring-core
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-83f7-v6px-pp3h Spring Framework Denial of Service via Multipart Requests in WebFlux | CVSS3: 5.9 | 0% Низкий | 3 месяца назад | |
GHSA-7phw-cxx7-q9vq Spring Framework is vulnerable to security bypass via mvcRequestMatcher pattern mismatch | CVSS3: 9.1 | 4% Низкий | больше 3 лет назад | |
GHSA-7p67-m4j8-h4vx A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier | CVSS3: 9.8 | 0% Низкий | 23 дня назад | |
GHSA-7m2p-62gw-p8qq Spring Framework Server-Side Request Forgery via UriComponentsBuilder | CVSS3: 4.2 | 0% Низкий | 3 месяца назад | |
GHSA-775g-4xr8-78h8 Spring Framework Denial of Service via Integer Overflow in SpEL Expressions | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
GHSA-72pg-x5f8-j25j Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux | CVSS3: 5.9 | 0% Низкий | 3 месяца назад | |
GHSA-6v7w-535j-rq5m Pivotal Spring Framework DoS Attack with XML Input | CVSS3: 5.5 | 3% Низкий | почти 8 лет назад | |
GHSA-6p4f-wcwh-5vvm Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources | CVSS3: 5.3 | 0% Низкий | 5 месяцев назад | |
GHSA-6hcq-hmm3-jj3c Spring MVC and WebFlux has Server Sent Event stream corruption | CVSS3: 2.6 | 0% Низкий | 6 месяцев назад | |
GHSA-659m-px2c-25wj Spring Framework Denial of Service via AntPathMatcher | CVSS3: 3.7 | 0% Низкий | 3 месяца назад | |
GHSA-5843-p793-ghmm Spring Framework DoS with Multipart Temp Files in WebFlux | CVSS3: 6.5 | 0% Низкий | 5 месяцев назад | |
GHSA-564r-hj7v-mcr5 Spring Framework vulnerable to denial of service via specially crafted SpEL expression | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
GHSA-558x-2xjg-6232 Allocation of Resources Without Limits or Throttling in Spring Framework | CVSS3: 6.5 | 36% Средний | больше 4 лет назад | |
GHSA-549f-4rpc-3rw9 Spring MVC and WebFlux applications that obtain a data-binding Errors instance with HTML escaping enabled and then render field errors using the no-argument Errors.getFieldErrors() or Errors.getFieldError() accessors are vulnerable to arbitrary HTML/JavaScript code injection, potentially resulting in a reflected cross-site scripting (XSS) vulnerability. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier | CVSS3: 6.1 | 0% Низкий | 22 дня назад | |
GHSA-53cv-4frm-9p27 A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 | CVSS3: 7.5 | 0% Низкий | 23 дня назад | |
GHSA-4wrc-f8pq-fpqp Pivotal Spring Framework contains unsafe Java deserialization methods | CVSS3: 9.8 | 32% Средний | больше 4 лет назад | |
GHSA-4hfh-6x8g-gwpp Spring Framework Escalation via Session Fixation in WebFlux | CVSS3: 4.2 | 0% Низкий | 3 месяца назад | |
GHSA-4gc7-5j7h-4qph Spring Framework DataBinder Case Sensitive Match Exception | CVSS3: 5.3 | 1% Низкий | почти 2 года назад | |
GHSA-4773-3jfm-qmx3 Spring Framework Improper Path Limitation with Script View Templates | CVSS3: 5.9 | 0% Низкий | 6 месяцев назад | |
GHSA-45vg-2v73-vm62 Moderate severity vulnerability that affects org.springframework:spring-core | 2% Низкий | почти 8 лет назад |
Уязвимостей на страницу