Skip to main content

Vendor/product archive

vmware / spring_framework CVEs

Beta · best-effort

67 CVEs tagged to vmware / spring_framework6 Critical, 18 High, 38 Medium, 5 Low, 0 Unrated.

CVE-2024-22233

Published Jan 22, 2024

In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifical…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34053

Published Nov 28, 2023

In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-20863

Published Apr 13, 2023

In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-ser…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-20860

Published Mar 27, 2023

Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-20861

Published Mar 23, 2023

In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafte…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-22950

Published Apr 1, 2022

n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of serv…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2021-22096

Published Oct 28, 2021

In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additio…

CVSS 4.3 · Medium

CVE-2016-1000027

Published Jan 2, 2020

Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2018-15801

Published Dec 19, 2018

Spring Security versions 5.1.x prior to 5.1.2 contain an authorization bypass vulnerability during JWT issuer validation. In order to be impacted, the same private key for an hone…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort
Showing 26-50 of 67 CVEsPage 2 of 3