Логотип exploitDog
bind:CVE-2026-22737
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-22737

Количество 4

Количество 4

redhat логотип

CVE-2026-22737

12 дней назад

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-22737

12 дней назад

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVSS3: 5.9
EPSS: Низкий
debian логотип

CVE-2026-22737

12 дней назад

Use of Java scripting engine enabled (e.g. JRuby, Jython) template vie ...

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-4773-3jfm-qmx3

12 дней назад

Spring Framework Improper Path Limitation with Script View Templates

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-22737

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVSS3: 6.5
0%
Низкий
12 дней назад
nvd логотип
CVE-2026-22737

Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.

CVSS3: 5.9
0%
Низкий
12 дней назад
debian логотип
CVE-2026-22737

Use of Java scripting engine enabled (e.g. JRuby, Jython) template vie ...

CVSS3: 5.9
0%
Низкий
12 дней назад
github логотип
GHSA-4773-3jfm-qmx3

Spring Framework Improper Path Limitation with Script View Templates

CVSS3: 5.9
0%
Низкий
12 дней назад

Уязвимостей на страницу