<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Spring Framework</title>
  <link>https://cvedaily.com/pages/tags/spring-framework.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/spring-framework.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Spring Framework</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:37 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2026-10153 – A flaw has been found in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c355...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-10153</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-10153</guid>
    <pubDate>Sat, 30 May 2026 22:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-10153</strong></p>
  <p>A flaw has been found in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. Impacted is the function Search of the file org/springframework/cache/support/AbstractCacheManager.java. This manipulation of the argument s causes cross site scripting. Remote exploitation of the attack is possible. The exploit has been published and may be used. This product follows a rolling release app…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-10153">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2026-22741 – Spring MVC and WebFlux applications are vulnerable to cache poisoning when resol...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22741</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22741</guid>
    <pubDate>Wed, 29 Apr 2026 12:16:18 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2026-22741</strong></p>
  <p>Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.   More precisely, an application can be vulnerable when all the following are true:    *  the application is using Spring MVC or Spring WebFlux   *  the application is configuring the  resource chain support https://docs.spring.io/spring-framework/reference/web/webmvc/mvc-config/static-resources…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-524</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22741">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-22750 – When configuring SSL bundles in Spring Cloud Gateway by using the configuration ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22750</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22750</guid>
    <pubDate>Fri, 10 Apr 2026 08:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-22750</strong></p>
  <p>When configuring SSL bundles in Spring Cloud Gateway by using the configuration property spring.ssl.bundle, the configuration was silently ignored and the default SSL configuration was used instead. Note: The 4.2.x branch is no longer under open source support. If you are using Spring Cloud Gateway 4.2.0 and are not an enterprise customer, you can upgrade to any Spring Cloud Gateway 4.2.x release…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-15</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22750">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-22737 – Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spri...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-22737</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-22737</guid>
    <pubDate>Fri, 20 Mar 2026 00:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-22737</strong></p>
  <p>Use of Java scripting engine enabled (e.g. JRuby, Jython) template views in Spring MVC and Spring WebFlux applications can result in disclosure of content from files outside the configured locations for script template views. This issue affects Spring Framework: from 7.0.0 through 7.0.5, from 6.2.0 through 6.2.16, from 6.1.0 through 6.1.25, from 5.3.0 through 5.3.46.</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-22737">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-41254 – STOMP over WebSocket applications may be vulnerable to a security bypass that al...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41254</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41254</guid>
    <pubDate>Thu, 16 Oct 2025 15:15:33 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-41254</strong></p>
  <p>STOMP over WebSocket applications may be vulnerable to a security bypass that allows an attacker to send unauthorized messages.  Affected Spring Products and VersionsSpring Framework:    *  6.2.0 - 6.2.11   *  6.1.0 - 6.1.23   *  6.0.x - 6.0.29   *  5.3.0 - 5.3.45   *  Older, unsupported versions are also affected.   MitigationUsers of affected versions should upgrade to the corresponding fixed v…</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41254">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-11226 – ACE vulnerability in conditional configuration file processing  by QOS.CH logbac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-11226</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-11226</guid>
    <pubDate>Wed, 01 Oct 2025 08:15:31 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-11226</strong></p>
  <p>ACE vulnerability in conditional configuration file processing  by QOS.CH logback-core up to and including version 1.5.18 in Java applications, allows an attacker to execute arbitrary code by compromising an existing logback configuration file or by injecting an environment variable before program execution.    A successful attack requires the presence of Janino library and Spring Framework to be…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-11226">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-41249 – The Spring Framework annotation detection mechanism may not correctly resolve an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41249</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41249</guid>
    <pubDate>Tue, 16 Sep 2025 11:15:30 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-41249</strong></p>
  <p>The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an issue if such annotations are used for authorization decisions.  Your application may be affected by this if you are using Spring Security's @EnableMethodSecurity feature.  You are not affected by this…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-285</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41249">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-58748 – Dataease is an open source data analytics and visualization platform. In Dataeas...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-58748</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-58748</guid>
    <pubDate>Mon, 15 Sep 2025 17:15:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-58748</strong></p>
  <p>Dataease is an open source data analytics and visualization platform. In Dataease versions up to 2.10.12 the H2 data source implementation (H2.java) does not verify that a provided JDBC URL starts with jdbc:h2. This lack of validation allows a crafted JDBC configuration that substitutes the Amazon Redshift driver and leverages the socketFactory and socketFactoryArg parameters to invoke org.spring…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-58748">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-41242 – Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnera...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41242</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41242</guid>
    <pubDate>Mon, 18 Aug 2025 09:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-41242</strong></p>
  <p>Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deployed on a non-compliant Servlet container.  An application can be vulnerable when all the following are true:    *  the application is deployed as a WAR or with an embedded Servlet container   *  the Servlet container  does not reject suspicious sequences https://jakarta.ee/specifications/servlet/6.1/…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41242">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-41234 – Description

In Spring Framework, versions 6.0.x as of 6.0.5, versions 6.1.x and...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-41234</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-41234</guid>
    <pubDate>Thu, 12 Jun 2025 22:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-41234</strong></p>
  <p>Description  In Spring Framework, versions 6.0.x as of 6.0.5, versions 6.1.x and 6.2.x, an application is vulnerable to a reflected file download (RFD) attack when it sets a “Content-Disposition” header with a non-ASCII charset, where the filename attribute is derived from user-supplied input.  Specifically, an application is vulnerable when all the following are true:    *  The header is prepare…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-113</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-41234">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-22233 – CVE-2024-38820 ensured Locale-independent, lowercase conversion for both the con...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-22233</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-22233</guid>
    <pubDate>Fri, 16 May 2025 20:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-22233</strong></p>
  <p>CVE-2024-38820 ensured Locale-independent, lowercase conversion for both the configured disallowedFields patterns and for request parameter names. However, there are still cases where it is possible to bypass the disallowedFields checks.  Affected Spring Products and Versions  Spring Framework:   *  6.2.0 - 6.2.6    *  6.1.0 - 6.1.19    *  6.0.0 - 6.0.27    *  5.3.0 - 5.3.42   *  Older, unsupport…</p>
  <p><strong>CVSS:</strong> 3.1 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-22233">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-55952 – DataEase is an open source business analytics tool. Authenticated users can remo...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-55952</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-55952</guid>
    <pubDate>Wed, 18 Dec 2024 19:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-55952</strong></p>
  <p>DataEase is an open source business analytics tool. Authenticated users can remotely execute code through the backend JDBC connection. When constructing the jdbc connection string, the parameters are not filtered. Constructing the host as ip:5432/test/?socketFactory=org.springframework.context.support.ClassPathXmlApplicationContext&socketFactoryArg=http://ip:5432/1.xml&a= can trigger the ClassPat…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-55952">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-38808 – In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-38808</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-38808</guid>
    <pubDate>Tue, 20 Aug 2024 08:15:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-38808</strong></p>
  <p>In Spring Framework versions 5.3.0 - 5.3.38 and older unsupported versions, it is possible for a user to provide a specially crafted Spring Expression Language (SpEL) expression that may cause a denial of service (DoS) condition.  Specifically, an application is vulnerable when the following is true:    *  The application evaluates user-supplied SpEL expressions.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-38808">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22259 – Applications that use UriComponentsBuilder in Spring Framework to parse an exter...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22259</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22259</guid>
    <pubDate>Sat, 16 Mar 2024 05:15:20 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22259</strong></p>
  <p>Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a  open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks.  This is the same as  CVE-2024-22243 http…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22259">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-22236 – In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22236</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22236</guid>
    <pubDate>Wed, 31 Jan 2024 07:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-22236</strong></p>
  <p>In Spring Cloud Contract, versions 4.1.x prior to 4.1.1, versions 4.0.x prior to 4.0.5, and versions 3.1.x prior to 3.1.10, test execution is vulnerable to local information disclosure via temporary directory created with unsafe permissions through the shaded com.google.guava:guava dependency in the org.springframework.cloud:spring-cloud-contract-shade dependency.</p>
  <p><strong>CVSS:</strong> 3.3 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22236">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-22233 – In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to prov...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-22233</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-22233</guid>
    <pubDate>Mon, 22 Jan 2024 13:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-22233</strong></p>
  <p>In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.  Specifically, an application is vulnerable when all of the following are true:    *  the application uses Spring MVC   *  Spring Security 6.1.6+ or 6.2.1+ is on the classpath   Typically, Spring Boot applications need the org.spri…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-22233">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-34055 – In Spring Boot versions 2.7.0 - 2.7.17, 3.0.0-3.0.12 and 3.1.0-3.1.5, it is poss...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34055</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34055</guid>
    <pubDate>Tue, 28 Nov 2023 09:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-34055</strong></p>
  <p>In Spring Boot versions 2.7.0 - 2.7.17, 3.0.0-3.0.12 and 3.1.0-3.1.5, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.  Specifically, an application is vulnerable when all of the following are true:    *  the application uses Spring MVC or Spring WebFlux   *  org.springframework.boot:spring-boot-actuator is on the classpath</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34055">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-34053 – In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provid...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34053</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34053</guid>
    <pubDate>Tue, 28 Nov 2023 09:15:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-34053</strong></p>
  <p>In Spring Framework versions 6.0.0 - 6.0.13, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.  Specifically, an application is vulnerable when all of the following are true:    *  the application uses Spring MVC or Spring WebFlux   *  io.micrometer:micrometer-core is on the classpath   *  an ObservationRegistry is configured…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34053">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-47174 – Thorn SFTP gateway 3.4.x before 3.4.4 uses Pivotal Spring Framework for Java des...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-47174</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-47174</guid>
    <pubDate>Tue, 31 Oct 2023 04:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-47174</strong></p>
  <p>Thorn SFTP gateway 3.4.x before 3.4.4 uses Pivotal Spring Framework for Java deserialization of untrusted data, which is not supported by Pivotal, a related issue to CVE-2016-1000027. Also, within the specific context of Thorn SFTP gateway, this leads to remote code execution.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-47174">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-20863 – In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20863</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20863</guid>
    <pubDate>Thu, 13 Apr 2023 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-20863</strong></p>
  <p>In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20863">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-20860 – Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20860</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20860</guid>
    <pubDate>Mon, 27 Mar 2023 22:15:21 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-20860</strong></p>
  <p>Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20860">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-20861 – In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-20861</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-20861</guid>
    <pubDate>Thu, 23 Mar 2023 21:15:19 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-20861</strong></p>
  <p>In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial-of-service (DoS) condition.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-20861">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-43484 – TERASOLUNA Global Framework 1.0.0 (Public review version) and TERASOLUNA Server ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-43484</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-43484</guid>
    <pubDate>Mon, 05 Dec 2022 04:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-43484</strong></p>
  <p>TERASOLUNA Global Framework 1.0.0 (Public review version) and TERASOLUNA Server Framework for Java (Rich) 2.0.0.2 to 2.0.5.1 are vulnerable to a ClassLoader manipulation vulnerability due to using the old version of Spring Framework which contains the vulnerability.The vulnerability is caused by an improper input validation issue in the binding mechanism of Spring MVC. By the application processi…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-43484">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-22971 – In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22971</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22971</guid>
    <pubDate>Thu, 12 May 2022 20:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-22971</strong></p>
  <p>In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket endpoint is vulnerable to a denial of service attack by an authenticated user.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22971">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-22970 – In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported vers...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22970</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22970</guid>
    <pubDate>Thu, 12 May 2022 20:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-22970</strong></p>
  <p>In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads are vulnerable to DoS attack if they rely on data binding to set a MultipartFile or javax.servlet.Part to a field in a model object.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22970">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-22968 – In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupport...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22968</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22968</guid>
    <pubDate>Thu, 14 Apr 2022 21:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-22968</strong></p>
  <p>In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedFields on a DataBinder are case sensitive which means a field is not effectively protected unless it is listed with both upper and lower case for the first character of the field, including upper and lower case for the first character of all nested fields within the property pat…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-178</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22968">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-22950 – n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-22950</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-22950</guid>
    <pubDate>Fri, 01 Apr 2022 23:15:13 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-22950</strong></p>
  <p>n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-770</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-22950">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-27772 – spring-boot versions prior to version v2.2.11.RELEASE was vulnerable to temporar...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-27772</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-27772</guid>
    <pubDate>Wed, 30 Mar 2022 18:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-27772</strong></p>
  <p>spring-boot versions prior to version v2.2.11.RELEASE was vulnerable to temporary directory hijacking. This vulnerability impacted the org.springframework.boot.web.server.AbstractConfigurableWebServerFactory.createTempDir method. NOTE: This vulnerability only affects products and/or versions that are no longer supported by the maintainer</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-668</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-27772">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-22060 – In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupport...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22060</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22060</guid>
    <pubDate>Mon, 10 Jan 2022 14:10:16 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-22060</strong></p>
  <p>In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22060">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-22096 – In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupport...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22096</guid>
    <pubDate>Thu, 28 Oct 2021 16:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-22096</strong></p>
  <p>In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-117</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22096">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-32602 – An improper neutralization of input during web page generation vulnerability (CW...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32602</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32602</guid>
    <pubDate>Thu, 19 Aug 2021 00:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-32602</strong></p>
  <p>An improper neutralization of input during web page generation vulnerability (CWE-79) in FortiPortal GUI 6.0.4 and below, 5.3.6 and below, 5.2.6 and below, 5.1.2 and below, 5.0.3 and below, 4.2.2 and below, 4.1.2 and below, 4.0.4 and below may allow a remote and unauthenticated attacker to perform an XSS attack via sending a crafted request with an invalid lang parameter or with an invalid org.sp…</p>
  <p><strong>CVSS:</strong> 5.8 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32602">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-29500 – bubble fireworks is an open source java package relating to Spring Framework. In...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-29500</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-29500</guid>
    <pubDate>Fri, 04 Jun 2021 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-29500</strong></p>
  <p>bubble fireworks is an open source java package relating to Spring Framework. In bubble fireworks before version 2021.BUILD-SNAPSHOT there is a vulnerability in which the package did not properly verify the signature of JSON Web Tokens. This allows to forgery of valid JWTs.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-347</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-29500">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-22118 – In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-22118</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-22118</guid>
    <pubDate>Thu, 27 May 2021 15:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-22118</strong></p>
  <p>In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or overwrite arbitrary files with multipart request data.</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-269</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-22118">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-5421 – In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-5421</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-5421</guid>
    <pubDate>Sat, 19 Sep 2020 04:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-5421</strong></p>
  <p>In Spring Framework versions 5.2.0 - 5.2.8, 5.1.0 - 5.1.17, 5.0.0 - 5.0.18, 4.3.0 - 4.3.28, and older unsupported versions, the protections against RFD attacks from CVE-2015-5211 may be bypassed depending on the browser used through the use of a jsessionid path parameter.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5421">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-11619 – FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction betwee...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-11619</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-11619</guid>
    <pubDate>Tue, 07 Apr 2020 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-11619</strong></p>
  <p>FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-11619">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-5397 – Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-5397</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-5397</guid>
    <pubDate>Fri, 17 Jan 2020 19:15:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-5397</strong></p>
  <p>Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not include credentials and therefore requests should fail authentication. However a notable exception to t…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5397">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-5398 – In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-5398</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-5398</guid>
    <pubDate>Fri, 17 Jan 2020 00:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-5398</strong></p>
  <p>In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-5398">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-6430 – The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-6430</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-6430</guid>
    <pubDate>Fri, 10 Jan 2020 14:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-6430</strong></p>
  <p>The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape certain characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a (1) line separator or (2) paragraph separator Unicode character or (3) left or (4) right angle bracket.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-6430">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-1000027 – Pivotal Spring Framework through 5.3.16 suffers from a potential remote code exe...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-1000027</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-1000027</guid>
    <pubDate>Thu, 02 Jan 2020 23:15:11 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-1000027</strong></p>
  <p>Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be change…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-1000027">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-15756 – Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x pr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-15756</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-15756</guid>
    <pubDate>Thu, 18 Oct 2018 22:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-15756</strong></p>
  <p>Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an org.springframework.core.io.Resource. A malicious user (or attacker) can add a range head…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-15756">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-11040 – Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and ol...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11040</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11040</guid>
    <pubDate>Mon, 25 Jun 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-11040</strong></p>
  <p>Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not enabled by default in Spring Framework nor Spring Boot, however, when MappingJackso…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-829</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11040">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-11039 – Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-11039</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-11039</guid>
    <pubDate>Mon, 25 Jun 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-11039</strong></p>
  <p>Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filter to escalate to an XST (Cross Site Tra…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-11039">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1258 – Spring Framework version 5.0.5 when used in combination with any versions of Spr...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1258</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1258</guid>
    <pubDate>Fri, 11 May 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1258</strong></p>
  <p>Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1258">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-1257 – Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1257</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1257</guid>
    <pubDate>Fri, 11 May 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-1257</strong></p>
  <p>Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a regular expression, denial of service attack.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1257">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-1275 – Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1275</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1275</guid>
    <pubDate>Wed, 11 Apr 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-1275</strong></p>
  <p>Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1275">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-1272 – Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1272</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1272</guid>
    <pubDate>Fri, 06 Apr 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-1272</strong></p>
  <p>Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote client, and then uses that input to make a multipart request to another server (server B), it can be exposed to an attack, where an extra multi…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1272">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-1271 – Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1271</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1271</guid>
    <pubDate>Fri, 06 Apr 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-1271</strong></p>
  <p>Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a request using a specially crafted URL that can lea…</p>
  <p><strong>CVSS:</strong> 5.9 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1271">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-1270 – Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1270</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1270</guid>
    <pubDate>Fri, 06 Apr 2018 13:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-1270</strong></p>
  <p>Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1270">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-1199 – Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-1199</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-1199</guid>
    <pubDate>Fri, 16 Mar 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-1199</strong></p>
  <p>Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.3.x before 4.3.14 and 5.0.x before 5.0.3) does not consider URL path parameters when processing security constraints. By adding a URL path parameter with special encodings, an attacker may be able to bypass a security constraint. The root cause of this issue is a lack of clarity…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-1199">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2017-8045 – In Pivotal Spring AMQP versions prior to 1.7.4, 1.6.11, and 1.5.7, an org.spring...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-8045</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-8045</guid>
    <pubDate>Mon, 27 Nov 2017 10:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2017-8045</strong></p>
  <p>In Pivotal Spring AMQP versions prior to 1.7.4, 1.6.11, and 1.5.7, an org.springframework.amqp.core.Message may be unsafely deserialized when being converted into a string. A malicious payload could be crafted to exploit this and enable a remote code execution attack.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-8045">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-8028 – In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP serve...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-8028</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-8028</guid>
    <pubDate>Mon, 27 Nov 2017 10:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-8028</strong></p>
  <p>In Pivotal Spring-LDAP versions 1.3.0 - 2.3.1, when connected to some LDAP servers, when no additional attributes are bound, and when using LDAP BindAuthenticator with org.springframework.ldap.core.support.DefaultTlsDirContextAuthenticationStrategy as the authentication strategy, and setting userSearch, authentication is allowed with an arbitrary password when the username is correct. This occurs…</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-287</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-8028">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2015-5258 – Cross-site request forgery (CSRF) vulnerability in springframework-social before...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5258</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5258</guid>
    <pubDate>Tue, 22 Aug 2017 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2015-5258</strong></p>
  <p>Cross-site request forgery (CSRF) vulnerability in springframework-social before 1.1.3.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5258">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-5007 – Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-5007</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-5007</guid>
    <pubDate>Thu, 25 May 2017 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-5007</strong></p>
  <p>Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mappings for authorization and for mapping requests to controllers respectively. Differences in the strictness of the pattern matching mechanisms, for example with regards to space trimming in path segments, can lead Spring Security to not recognize certain paths as not protected that…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-5007">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2015-5211 – Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-5211</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-5211</guid>
    <pubDate>Thu, 25 May 2017 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2015-5211</strong></p>
  <p>Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some input reflected in the response.</p>
  <p><strong>CVSS:</strong> 9.6 · <strong>CWE:</strong> CWE-552</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-5211">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2014-0225 – When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-0225</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-0225</guid>
    <pubDate>Thu, 25 May 2017 17:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2014-0225</strong></p>
  <p>When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-611</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0225">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2016-2173 – org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-2173</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-2173</guid>
    <pubDate>Fri, 21 Apr 2017 20:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2016-2173</strong></p>
  <p>org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-2173">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-9878 – An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-9878</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-9878</guid>
    <pubDate>Thu, 29 Dec 2016 09:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-9878</strong></p>
  <p>An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-9878">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-0635 – Unspecified vulnerability in the Enterprise Manager Ops Center component in Orac...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-0635</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-0635</guid>
    <pubDate>Thu, 21 Jul 2016 10:12:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-0635</strong></p>
  <p>Unspecified vulnerability in the Enterprise Manager Ops Center component in Oracle Enterprise Manager Grid Control 12.1.4, 12.2.2, and 12.3.2; the Oracle Health Sciences Information Manager component in Oracle Health Sciences Applications 1.2.8.3, 2.0.2.3, and 3.0.1.0; the Oracle Healthcare Master Person Index component in Oracle Health Sciences Applications 2.0.12, 3.0.0, and 4.0.1; the Oracle D…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-0635">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-3192 – Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly proc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-3192</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-3192</guid>
    <pubDate>Tue, 12 Jul 2016 19:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-3192</strong></p>
  <p>Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) via a crafted XML file.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-3192">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-0201 – The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-0201</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-0201</guid>
    <pubDate>Tue, 10 Mar 2015 14:59:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-0201</strong></p>
  <p>The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-254</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-0201">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-3578 – Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 a...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-3578</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-3578</guid>
    <pubDate>Thu, 19 Feb 2015 20:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-3578</strong></p>
  <p>Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3578">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-3625 – Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-3625</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-3625</guid>
    <pubDate>Thu, 20 Nov 2014 17:50:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-3625</strong></p>
  <p>Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-3625">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-0054 – The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework befor...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-0054</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-0054</guid>
    <pubDate>Thu, 17 Apr 2014 14:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-0054</strong></p>
  <p>The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue.  NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4152…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-0054">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-1904 – Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java i...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-1904</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-1904</guid>
    <pubDate>Thu, 20 Mar 2014 16:55:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-1904</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the requested URI in a default action.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-1904">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-6429 – The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 an...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-6429</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-6429</guid>
    <pubDate>Sun, 26 Jan 2014 16:58:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-6429</strong></p>
  <p>The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152 and CVE-2013-7315.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-6429">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-7315 – The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 do...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-7315</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-7315</guid>
    <pubDate>Thu, 23 Jan 2014 21:55:05 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-7315</strong></p>
  <p>The Spring MVC in Spring Framework before 3.2.4 and 4.0.0.M1 through 4.0.0.M2 does not disable external entity resolution for the StAX XMLInputFactory, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML with JAXB, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013-4152.  NOTE: this…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-7315">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-4152 – The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-4152</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-4152</guid>
    <pubDate>Thu, 23 Jan 2014 21:55:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-4152</strong></p>
  <p>The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource, (2) StAXSource, (3) SAXSource, or (4) Stream…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-4152">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2011-2730 – VMware SpringSource Spring Framework before 2.5.6.SEC03, 2.5.7.SR023, and 3.x be...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-2730</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-2730</guid>
    <pubDate>Wed, 05 Dec 2012 17:55:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2011-2730</strong></p>
  <p>VMware SpringSource Spring Framework before 2.5.6.SEC03, 2.5.7.SR023, and 3.x before 3.0.6, when a container supports Expression Language (EL), evaluates EL expressions in tags twice, which allows remote attackers to obtain sensitive information via a (1) name attribute in a (a) spring:hasBindErrors tag; (2) path attribute in a (b) spring:bind or (c) spring:nestedpath tag; (3) arguments, (4) code…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-16</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-2730">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2012-0936 – Cross-site scripting (XSS) vulnerability in web/springframework/security/Securit...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-0936</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-0936</guid>
    <pubDate>Sun, 29 Jan 2012 04:04:45 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2012-0936</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in web/springframework/security/SecurityAuthenticationEventOnmsEventBuilder.java in OpenNMS 1.8.x before 1.8.17, 1.9.93 and earlier, and 1.10.x before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via the Username field, related to login.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-0936">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-2894 – Spring Framework 3.0.0 through 3.0.5, Spring Security 3.0.0 through 3.0.5 and 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-2894</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-2894</guid>
    <pubDate>Tue, 04 Oct 2011 10:55:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-2894</strong></p>
  <p>Spring Framework 3.0.0 through 3.0.5, Spring Security 3.0.0 through 3.0.5 and 2.0.0 through 2.0.6, and possibly other versions deserialize objects from untrusted sources, which allows remote attackers to bypass intended security restrictions and execute untrusted code by (1) serializing a java.lang.Proxy instance and using InvocationHandler, or (2) accessing internal AOP interfaces, as demonstrat…</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-502</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-2894">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2010-1622 – SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2010-1622</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2010-1622</guid>
    <pubDate>Mon, 21 Jun 2010 16:30:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2010-1622</strong></p>
  <p>SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar file.</p>
  <p><strong>CVSS:</strong> 6.0 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2010-1622">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2009-1190 – Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile meth...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2009-1190</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2009-1190</guid>
    <pubDate>Mon, 27 Apr 2009 22:30:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2009-1190</strong></p>
  <p>Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows remote attackers to cause a denial of service (CPU consumption) via serializable data with a long regex string containi…</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-399</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2009-1190">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
