Spring security incidents

Recent advisories touching Spring apps — searchable, enriched with exploit probability and affected versions.

HIGHMaven

Spring Data: Unbounded property-path cache keyed by externally-supplied path string

Spring Data: Unbounded property-path cache keyed by externally-supplied path string

org.springframework.data:spring-data-commons: 4.0.0 → 4.0.6

5 days agoEPSS 0%
MEDIUMMaven

Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL

Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL

org.springframework:spring-webflux: all versions

1 month agoEPSS 0%
HIGHMaven

Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux

Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

1 month agoEPSS 0%
HIGHMaven

Spring Framework Cross-site Scripting via JSP Form Tags

Spring Framework Cross-site Scripting via JSP Form Tags

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

1 month agoEPSS 0%
HIGHMaven

Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux

Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

1 month agoEPSS 0%
MEDIUMMaven

Spring Framework Arbitrary Method Invocation in SpEL Expressions

Spring Framework Arbitrary Method Invocation in SpEL Expressions

org.springframework:spring-expression: 7.0.0 → 7.0.8

1 month agoEPSS 0%
MEDIUMMaven

Spring Framework Open Redirect in Spring MVC and WebFlux

Spring Framework Open Redirect in Spring MVC and WebFlux

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

1 month agoEPSS 0%
HIGHMaven

Spring Framework Algorithmic Denial of Service via SpEL Expressions

Spring Framework Algorithmic Denial of Service via SpEL Expressions

org.springframework:spring-expression: 7.0.0 → 7.0.8

1 month agoEPSS 0%
HIGHMaven

Spring Framework Cross-site Scripting via JavaScriptUtils

Spring Framework Cross-site Scripting via JavaScriptUtils

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

1 month agoEPSS 0%
MEDIUMMaven

Spring Framework Denial of Service via Unbounded Cache in SpEL

Spring Framework Denial of Service via Unbounded Cache in SpEL

org.springframework:spring-expression: 7.0.0 → 7.0.8

1 month agoEPSS 0%
MEDIUMMaven

Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux

Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

1 month agoEPSS 0%
MEDIUMMaven

Spring Framework Escalation via Session Fixation in WebFlux

Spring Framework Escalation via Session Fixation in WebFlux

org.springframework:spring-webflux: 7.0.0 → 7.0.8

1 month agoEPSS 0%
HIGHMaven

Spring Framework Denial of Service via Integer Overflow in SpEL Expressions

Spring Framework Denial of Service via Integer Overflow in SpEL Expressions

org.springframework:spring-expression: all versions

1 month agoEPSS 0%
HIGHMaven

Spring Framework Denial of Service via Multipart Requests in WebFlux

Spring Framework Denial of Service via Multipart Requests in WebFlux

org.springframework:spring-webflux: 7.0.0 → 7.0.8

1 month agoEPSS 0%
HIGHMaven

Spring LDAP has Authentication Bypass with Empty Password

Spring LDAP has Authentication Bypass with Empty Password

org.springframework.ldap:spring-ldap-core: 4.0.0 → 4.0.4

1 month agoEPSS 0%
HIGHMaven

Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux

Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux

org.springframework:spring-webmvc: 7.0.0 → 7.0.8

1 month agoEPSS 0%
HIGHMaven

Spring Framework Predictable Session ID in WebSocket Module

Spring Framework Predictable Session ID in WebSocket Module

org.springframework:spring-websocket: 7.0.0 → 7.0.8

1 month agoEPSS 0%
HIGHMaven

Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration

Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration

org.springframework.hateoas:spring-hateoas: 3.0.0 → 3.0.4

1 month agoEPSS 0%
HIGHMaven

Spring Retry has Cache Exhaustion in Stateful Retries that leads to Denial of Service

Spring Retry has Cache Exhaustion in Stateful Retries that leads to Denial of Service

org.springframework.retry:spring-retry: 2.0.0 → 2.0.13

1 month agoEPSS 0%
HIGHMaven

Spring HATEOAS heap exhaustion through unbounded internal caching

Spring HATEOAS heap exhaustion through unbounded internal caching

org.springframework.hateoas:spring-hateoas: 3.0.0 → 3.0.4

1 month agoEPSS 0%
MEDIUMMaven

Spring Framework Denial of Service via AntPathMatcher

Spring Framework Denial of Service via AntPathMatcher

org.springframework:spring-core: 7.0.0 → 7.0.8

1 month agoEPSS 0%
CRITICALExploitedunknown

VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability

https://tanzu.vmware.com/security/cve-2022-22963; https://nvd.nist.gov/vuln/detail/CVE-2022-22963

3 years agoEPSS 100%
CRITICALExploitedunknown

VMware Spring Cloud Gateway Code Injection Vulnerability

https://nvd.nist.gov/vuln/detail/CVE-2022-22947

4 years agoEPSS 98%
CRITICALExploitedunknown

Spring Framework JDK 9+ Remote Code Execution Vulnerability

https://nvd.nist.gov/vuln/detail/CVE-2022-22965

4 years agoEPSS 100%
CRITICALExploitedunknown

VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability

https://nvd.nist.gov/vuln/detail/CVE-2020-5410

4 years agoEPSS 96%
CRITICALExploitedunknown

VMware Tanzu Spring Data Commons Property Binder Vulnerability

https://nvd.nist.gov/vuln/detail/CVE-2018-1273

4 years agoEPSS 96%

Tooling for Spring

SnykScan your dependencies in CI and fix this vulnerability.SocketDetect malicious and compromised packages before they ship.

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.