Skip to main content

Vendor/product archive

pivotal_software / spring_framework CVEs

Beta · best-effort

10 CVEs tagged to pivotal_software / spring_framework0 Critical, 3 High, 7 Medium, 0 Low, 0 Unrated.

CVE-2013-6430

Published Jan 10, 2020

The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape certain characters, which allo…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-3578

Published Feb 19, 2015

Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-1904

Published Mar 20, 2014

Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-10 of 10 CVEsPage 1 of 1