Spring security incidents
Recent advisories touching Spring apps — searchable, enriched with exploit probability and affected versions.
Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypass
Handlebars.java: Arbitrary file read in `SpringTemplateLoader` via URL-fragment suffix bypass
com.github.jknack:handlebars-springmvc: before 4.5.3
A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6
A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.0.RELEASE - 5.2.25.RELEASE
The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framew
The PartEventHttpMessageReader in Spring WebFlux does not enforce the maxPartSize limit when maxInMemorySize is set to -1. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28
Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specifi
Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Fram
UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or B
Applications that evaluate user-supplied Spring Expression Language (SpEL) expressions may be vulnerable to a Denial of Service (DoS) attack when the power operator (^) is used with a BigDecimal or BigInteger operand and a large exponent value. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.
A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the maxInMemorySize limit. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framework 7.0.0 - 7.0.8 Spring Fram
A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.5.RELEASE - 5.2.25.RELEASE
A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.
A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason. Spring Framework 7.0.0 - 7.0.8 S
A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
Malicious code in motionspring (npm)
Malicious code in motionspring (npm)
Spring Data: Unbounded property-path cache keyed by externally-supplied path string
Spring Data: Unbounded property-path cache keyed by externally-supplied path string
org.springframework.data:spring-data-commons: 4.0.0 → 4.0.6
Apache Camel-Langchain4j-Tools: Tool argument headers are not filtered against declared parameters
Apache Camel-Langchain4j-Tools: Tool argument headers are not filtered against declared parameters
org.apache.camel:camel-langchain4j-tools: 4.8.0 → 4.18.3
Spring AI vector store metadata filtering to handle special characters in Elasticsearch, OpenSearch, and GemFire Vector Stores
Spring AI vector store metadata filtering to handle special characters in Elasticsearch, OpenSearch, and GemFire Vector Stores
org.springframework.ai:spring-ai-opensearch-store: 1.0.0 → 1.0.9
Spring Cloud Sleuth instrumentation of Spring TX DoS vulnerability
Spring Cloud Sleuth instrumentation of Spring TX DoS vulnerability
org.springframework.cloud:spring-cloud-sleuth-instrumentation: ≥ 3.1.0
Spring Web Services: Wss4jSecurityInterceptor disables WS-I BSP validation by default
Spring Web Services: Wss4jSecurityInterceptor disables WS-I BSP validation by default
org.springframework.ws:spring-ws-security: 5.0.0 → 5.0.2
Spring Integration File Support: FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem
Spring Integration File Support: FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem
org.springframework.integration:spring-integration-file: 7.0.0 → 7.0.5
Spring Boot: Predictable Temp Directory in Artemis Auto-configuration
Spring Boot: Predictable Temp Directory in Artemis Auto-configuration
org.springframework.boot:spring-boot-autoconfigure: 4.0.0 → 4.0.7
Spring Web Flow JS RemotingHandler renders non-HTML Response as HTML
Spring Web Flow JS RemotingHandler renders non-HTML Response as HTML
org.springframework.webflow:spring-webflow: 4.0.0 → 4.0.1
Spring Boot's Mail Auto-Configuration Does Not Enable SSL Hostname Verification
Spring Boot's Mail Auto-Configuration Does Not Enable SSL Hostname Verification
org.springframework.boot:spring-boot-starter-mail: 4.0.0 → 4.0.7
Spring Web Flow has Data Binding Vulnerability with Unified EL Parser
Spring Web Flow has Data Binding Vulnerability with Unified EL Parser
org.springframework.webflow:spring-webflow: 4.0.0 → 4.0.1
Spring for GraphQL: Annotation Detection Vulnerability
Spring for GraphQL: Annotation Detection Vulnerability
org.springframework.graphql:spring-graphql: 2.0.0 → 2.0.4
Spring for GraphQL: Unsafe Deserialization
Spring for GraphQL: Unsafe Deserialization
org.springframework.graphql:spring-graphql: 2.0.0 → 2.0.4
Spring for GraphQL: Cross-Site WebSocket Hijacking
Spring for GraphQL: Cross-Site WebSocket Hijacking
org.springframework.graphql:spring-graphql: 2.0.0 → 2.0.4
Spring Web Services: SSRF via unvalidated WS-Addressing reply destinations
Spring Web Services: SSRF via unvalidated WS-Addressing reply destinations
org.springframework.ws:spring-ws-core: 5.0.0 → 5.0.2
Spring Web Services: SOAP security faults leak Spring Security account state
Spring Web Services: SOAP security faults leak Spring Security account state
org.springframework.ws:spring-ws-security: 5.0.0 → 5.0.2
Spring Web Services: WSS4J validation does not use configured replay cache
Spring Web Services: WSS4J validation does not use configured replay cache
org.springframework.ws:spring-ws-security: 5.0.0 → 5.0.2
Spring Web Services: X.509 authentication bypasses Spring Security account checks
Spring Web Services: X.509 authentication bypasses Spring Security account checks
org.springframework.ws:spring-ws-security: 5.0.0 → 5.0.2
Spring Web Services: Inbound WS-Security allows RSA PKCS#1 v1.5 key transport by default
Spring Web Services: Inbound WS-Security allows RSA PKCS#1 v1.5 key transport by default
org.springframework.ws:spring-ws-security: 5.0.0 → 5.0.2
Spring Web Services: Jaxp13 XPath XXE via StreamSource and SAXSource
Spring Web Services: Jaxp13 XPath XXE via StreamSource and SAXSource
org.springframework.ws:spring-xml: 5.0.0 → 5.0.2
Spring Security SAML2 Service Provider: RelyingPartyRegistration may run arbitrary code on HTML forms generated by Spring Security filters
Spring Security SAML2 Service Provider: RelyingPartyRegistration may run arbitrary code on HTML forms generated by Spring Security filters
org.springframework.security:spring-security-saml2-service-provider: 7.0.0 → 7.0.6
Spring AMQP Core: Missing Certificate and Hostname Verification for amqps URIs in RabbitConnectionFactoryBean
Spring AMQP Core: Missing Certificate and Hostname Verification for amqps URIs in RabbitConnectionFactoryBean
org.springframework.amqp:spring-amqp: 4.0.0 → 4.0.4
Spring for Apache Kafka: Improper Validation of Retry Topic Header Values Leads to Retry Sequence Manipulation
Spring for Apache Kafka: Improper Validation of Retry Topic Header Values Leads to Retry Sequence Manipulation
org.springframework.kafka:spring-kafka: 4.0.0 → 4.0.6
Spring Data Commons: StackOverflowException when parsing Sort parameters (DoS)
Spring Data Commons: StackOverflowException when parsing Sort parameters (DoS)
org.springframework.data:spring-data-commons: 4.0.0 → 4.0.6
Spring Data KeyValue: Remote code execution via SpEL Injection in Sort-based repository queries
Spring Data KeyValue: Remote code execution via SpEL Injection in Sort-based repository queries
org.springframework.data:spring-data-keyvalue: 4.0.0 → 4.0.6
Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates
Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates
org.springframework.security:spring-security-web: 6.5.0 → 6.5.11
Spring Data Commons: Denial of Service via excessive memory allocation in projection binding
Spring Data Commons: Denial of Service via excessive memory allocation in projection binding
org.springframework.data:spring-data-commons: 4.0.0 → 4.0.6
Spring Security: Open Redirect via Unvalidated Post-Login Redirect URL Stored in CookieRequestCache
Spring Security: Open Redirect via Unvalidated Post-Login Redirect URL Stored in CookieRequestCache
org.springframework.security:spring-security-web: 7.0.0 → 7.0.6
Spring Data Commons: Heap exhaustion from unbounded property-lookup cache retaining crafted string keys
Spring Data Commons: Heap exhaustion from unbounded property-lookup cache retaining crafted string keys
org.springframework.data:spring-data-commons: 4.0.0 → 4.0.6
Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch requests
Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch requests
org.springframework.data:spring-data-rest-core: 5.0.0 → 5.0.6
Spring Data REST potentially exposes persistence-layer internals to HTTP clients
Spring Data REST potentially exposes persistence-layer internals to HTTP clients
org.springframework.data:spring-data-rest-core: 5.0.0 → 5.0.6
Spring Security SAML2 Service Provider: Decryption Oracle Vulnerability from Unsigned SAML Response and Logout Payloads
Spring Security SAML2 Service Provider: Decryption Oracle Vulnerability from Unsigned SAML Response and Logout Payloads
org.springframework.security:spring-security-saml2-service-provider: 7.0.0 → 7.0.6
Spring AMQP Has Predictable Correlation IDs in RabbitTemplate.sendAndReceive() with Fixed Reply Queue
Spring AMQP Has Predictable Correlation IDs in RabbitTemplate.sendAndReceive() with Fixed Reply Queue
org.springframework.amqp:spring-amqp: 4.0.0 → 4.0.4
Spring Security SAML2 Service Provider is vulnerable to Deserialization of Untrusted Data via JdbcAssertingPartyMetadataRepository
Spring Security SAML2 Service Provider is vulnerable to Deserialization of Untrusted Data via JdbcAssertingPartyMetadataRepository
org.springframework.security:spring-security-saml2-service-provider: 7.0.0 → 7.0.6
Spring Data Relational: Attackers can supply wildcard characters to perform boolean-based blind data inference
Spring Data Relational: Attackers can supply wildcard characters to perform boolean-based blind data inference
org.springframework.data:spring-data-relational: 4.0.0 → 4.0.6
Spring Data REST Querydsl Integration Exposes Persistent Property Paths, Bypassing Jackson Customizations
Spring Data REST Querydsl Integration Exposes Persistent Property Paths, Bypassing Jackson Customizations
org.springframework.data:spring-data-rest-core: 5.0.0 → 5.0.6
Spring Security OAuth2 Authorization Server: Authorization endpoint performs insufficient validation of the request_uri parameter
Spring Security OAuth2 Authorization Server: Authorization endpoint performs insufficient validation of the request_uri parameter
org.springframework.security:spring-security-oauth2-authorization-server: 7.0.0 → 7.0.6
Spring Data MongoDB is vulnerable to SpEL (Spring Expression Language) expression injection
Spring Data MongoDB is vulnerable to SpEL (Spring Expression Language) expression injection
org.springframework.data:spring-data-mongodb: 5.0.0 → 5.0.6
Spring Security SAML2 Service Provider: Unbounded writer inflates the compressed SAML payload into memory (DoS)
Spring Security SAML2 Service Provider: Unbounded writer inflates the compressed SAML payload into memory (DoS)
org.springframework.security:spring-security-saml2-service-provider: 7.0.0 → 7.0.6
Spring Data REST has Improper Access Control in its JSON Patch Implementation
Spring Data REST has Improper Access Control in its JSON Patch Implementation
org.springframework.data:spring-data-rest-core: 5.0.0 → 5.0.6
Spring for Apache Pulsar: JsonPulsarHeaderMapper Trusted-Package Prefix Check Allows Unintended Subpackage Deserialization
Spring for Apache Pulsar: JsonPulsarHeaderMapper Trusted-Package Prefix Check Allows Unintended Subpackage Deserialization
org.springframework.pulsar:spring-pulsar: 2.0.0 → 2.0.6
Spring REST Docs REST Assured & WebFlux are vulnerable to Improper Restriction of XML External Entity Reference
Spring REST Docs REST Assured & WebFlux are vulnerable to Improper Restriction of XML External Entity Reference
org.springframework.restdocs:spring-restdocs-webtestclient: 4.0.0 → 4.0.1
Spring Data MongoDB Has Regex Parameter Binding Injection in @Query Repository Methods
Spring Data MongoDB Has Regex Parameter Binding Injection in @Query Repository Methods
org.springframework.data:spring-data-mongodb: 5.0.0 → 5.0.6
Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL
Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL
org.springframework:spring-webflux: all versions
Spring Framework Denial of Service via Integer Overflow in SpEL Expressions
Spring Framework Denial of Service via Integer Overflow in SpEL Expressions
org.springframework:spring-expression: all versions
Spring Framework Predictable Session ID in WebSocket Module
Spring Framework Predictable Session ID in WebSocket Module
org.springframework:spring-websocket: 7.0.0 → 7.0.8
Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration
Spring HATEOAS Collection+JSON/UBER deserializers do not honor Jackson configuration
org.springframework.hateoas:spring-hateoas: 3.0.0 → 3.0.4
Spring Retry has Cache Exhaustion in Stateful Retries that leads to Denial of Service
Spring Retry has Cache Exhaustion in Stateful Retries that leads to Denial of Service
org.springframework.retry:spring-retry: 2.0.0 → 2.0.13
Spring HATEOAS heap exhaustion through unbounded internal caching
Spring HATEOAS heap exhaustion through unbounded internal caching
org.springframework.hateoas:spring-hateoas: 3.0.0 → 3.0.4
Spring Framework Server-Side Request Forgery via UriComponentsBuilder
Spring Framework Server-Side Request Forgery via UriComponentsBuilder
org.springframework:spring-web: 7.0.0 → 7.0.8
Spring Framework Unsafe Deserialization via Jackson JMS Converters
Spring Framework Unsafe Deserialization via Jackson JMS Converters
org.springframework:spring-jms: all versions
Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux
Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Spring LDAP has Authentication Bypass with Empty Password
Spring LDAP has Authentication Bypass with Empty Password
org.springframework.ldap:spring-ldap-core: 4.0.0 → 4.0.4
Spring Framework Denial of Service via Multipart Requests in WebFlux
Spring Framework Denial of Service via Multipart Requests in WebFlux
org.springframework:spring-webflux: 7.0.0 → 7.0.8
Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux
Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Spring Framework Algorithmic Denial of Service via SpEL Expressions
Spring Framework Algorithmic Denial of Service via SpEL Expressions
org.springframework:spring-expression: 7.0.0 → 7.0.8
Spring Framework Denial of Service via Unbounded Cache in SpEL
Spring Framework Denial of Service via Unbounded Cache in SpEL
org.springframework:spring-expression: 7.0.0 → 7.0.8
Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux
Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Spring Framework Cross-site Scripting via JavaScriptUtils
Spring Framework Cross-site Scripting via JavaScriptUtils
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Spring Framework Arbitrary Method Invocation in SpEL Expressions
Spring Framework Arbitrary Method Invocation in SpEL Expressions
org.springframework:spring-expression: 7.0.0 → 7.0.8
Spring Framework Open Redirect in Spring MVC and WebFlux
Spring Framework Open Redirect in Spring MVC and WebFlux
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Spring Framework Cross-site Scripting via JSP Form Tags
Spring Framework Cross-site Scripting via JSP Form Tags
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux
Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux
org.springframework:spring-webmvc: 7.0.0 → 7.0.8
Spring Framework Escalation via Session Fixation in WebFlux
Spring Framework Escalation via Session Fixation in WebFlux
org.springframework:spring-webflux: 7.0.0 → 7.0.8
Spring Framework Denial of Service via AntPathMatcher
Spring Framework Denial of Service via AntPathMatcher
org.springframework:spring-core: 7.0.0 → 7.0.8
Spring AI: ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage
Spring AI: ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage
org.springframework.ai:spring-ai-client-chat: before 1.0.7
Spring Framework DoS with Multipart Temp Files in WebFlux
Spring Framework DoS with Multipart Temp Files in WebFlux
org.springframework:spring-webflux: 7.0.0 → 7.0.7
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.
org.springframework:spring-webflux: 7.0.0 → 7.0.7
Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources
Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources
org.springframework:spring-webflux: 7.0.0 → 7.0.7
Spring Boot's default security filter chain has no authorization rule with Actuator but without Health
Spring Boot's default security filter chain has no authorization rule with Actuator but without Health
org.springframework.boot:spring-boot: 4.0.0 → 4.0.6
Spring Boot accepts predictable temp directory without ownership verification
Spring Boot accepts predictable temp directory without ownership verification
org.springframework.boot:spring-boot: 4.0.0 → 4.0.6
Spring Security has Potential Security Misconfiguration when Using withIssuerLocation
Spring Security has Potential Security Misconfiguration when Using withIssuerLocation
org.springframework.security:spring-security-oauth2-jose: ≥ 6.3.0
Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates
Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates
org.springframework.security:spring-security-web: 7.0.0 → 7.0.5
Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider
Spring Security Vulnerable to User Attribute Enumeration when Using DaoAuthenticationProvider
org.springframework.security:spring-security-core: ≥ 5.7.0
Spring Security Doesn't Correctly Include Servlet Path in Path Matching of HttpSecurity#securityMatchers
Spring Security Doesn't Correctly Include Servlet Path in Path Matching of HttpSecurity#securityMatchers
org.springframework.security:spring-security-config: 7.0.0 → 7.0.5
Spring Security Doesn't Correctly Include Servlet Path in Path Matching of XML Authorization Rules
Spring Security Doesn't Correctly Include Servlet Path in Path Matching of XML Authorization Rules
org.springframework.security:spring-security-config: 7.0.0 → 7.0.5
Spring Security Core has a TOCTOU race condition when One-Time Token login with JdbcOneTimeTokenService is configured
Spring Security Core has a TOCTOU race condition when One-Time Token login with JdbcOneTimeTokenService is configured
org.springframework.security:spring-security-core: 6.5.0 → 6.5.10
Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpoints
Spring Boot has an Authentication Bypass under Actuator CloudFoundry endpoints
org.springframework.boot:spring-boot-starter-actuator: 4.0.0-M1 → 4.0.4
Spring Security HTTP Headers Are not Written Under Some Conditions
Spring Security HTTP Headers Are not Written Under Some Conditions
org.springframework.security:spring-security-web: all versions
Spring MVC and WebFlux has Server Sent Event stream corruption
Spring MVC and WebFlux has Server Sent Event stream corruption
org.springframework:spring-webmvc: 7.0.0-M1 → 7.0.6
Spring Framework Improper Path Limitation with Script View Templates
Spring Framework Improper Path Limitation with Script View Templates
org.springframework:spring-webmvc: 7.0.0-M1 → 7.0.6
Spring Boot has an Authentication Bypass under Actuator Health groups paths
Spring Boot has an Authentication Bypass under Actuator Health groups paths
org.springframework.boot:spring-boot-starter-actuator: ≥ 3.4.0
Apache Shiro has an Authentication Bypass
Apache Shiro has an Authentication Bypass
org.apache.shiro:shiro-spring: before 2.1.0
Spring Framework STOMP over WebSocket applications may allow attackers to send unauthorized messages
Spring Framework STOMP over WebSocket applications may allow attackers to send unauthorized messages
org.springframework:spring-websocket: 6.2.0 → 6.2.12
Spring Framework annotation detection mechanism may result in improper authorization
Spring Framework annotation detection mechanism may result in improper authorization
org.springframework:spring-core: ≥ 5.3.0
Spring Security annotation detection mechanism has authorization bypass
Spring Security annotation detection mechanism has authorization bypass
org.springframework.security:spring-security-core: 6.4.0 → 6.4.10
Spring Framework MVC Applications Path Traversal Vulnerability
Spring Framework MVC Applications Path Traversal Vulnerability
org.springframework:spring-webmvc: 6.2.0 → 6.2.10
Spring Framework vulnerable to a reflected file download (RFD)
Spring Framework vulnerable to a reflected file download (RFD)
org.springframework:spring-web: 6.2.0 → 6.2.8
Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies
Spring Cloud Gateway Server Forwards Headers from Untrusted Proxies
org.springframework.cloud:spring-cloud-gateway-server: 4.2.0 → 4.2.3
Spring Framework DataBinder Case Sensitive Match Exception
Spring Framework DataBinder Case Sensitive Match Exception
org.springframework:spring-context: 6.2.0 → 6.2.7
Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed
Spring Boot EndpointRequest.to() creates wrong matcher if actuator endpoint is not exposed
org.springframework.boot:spring-boot: all versions
Spring Security Vulnerable to Authorization Bypass via Security Annotations
Spring Security Vulnerable to Authorization Bypass via Security Annotations
org.springframework.security:spring-security-core: 6.4.0 → 6.4.4
Spring Security Does Not Enforce Password Length
Spring Security Does Not Enforce Password Length
org.springframework.security:spring-security-crypto: 6.3.0 → 6.3.8
Spring LDAP data exposure vulnerability
Spring LDAP data exposure vulnerability
org.springframework.ldap:spring-ldap-core: 3.0.0 → 3.2.8
Spring Framework has Authorization Bypass for Case Sensitive Comparisons
Spring Framework has Authorization Bypass for Case Sensitive Comparisons
org.springframework.security:spring-security-core: before 5.7.14
Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications
Spring Security vulnerable to Authorization Bypass of Static Resources in WebFlux Applications
org.springframework.security:spring-security-web: 5.0.0 → 5.7.13
Spring Framework DataBinder Case Sensitive Match Exception
Spring Framework DataBinder Case Sensitive Match Exception
org.springframework:spring-context: 6.1.0 → 6.1.14
Spring Framework DoS via conditional HTTP request
Spring Framework DoS via conditional HTTP request
org.springframework:spring-web: before 5.3.38
Path traversal vulnerability in functional web frameworks
Path traversal vulnerability in functional web frameworks
org.springframework:spring-webmvc: 6.1.0 → 6.1.13
Spring Framework vulnerable to Denial of Service
Spring Framework vulnerable to Denial of Service
org.springframework:spring-expression: before 5.3.39
Spring Framework URL Parsing with Host Validation
Spring Framework URL Parsing with Host Validation
org.springframework:spring-web: before 5.3.34
Erroneous authentication pass in Spring Security
Erroneous authentication pass in Spring Security
org.springframework.security:spring-security-core: before 5.7.12
Spring Framework URL Parsing with Host Validation Vulnerability
Spring Framework URL Parsing with Host Validation Vulnerability
org.springframework:spring-web: 6.1.0 → 6.1.5
Spring Web vulnerable to Open Redirect or Server Side Request Forgery
Spring Web vulnerable to Open Redirect or Server Side Request Forgery
org.springframework:spring-web: 6.1.0 → 6.1.4
Spring Framework server Web DoS Vulnerability
Spring Framework server Web DoS Vulnerability
org.springframework:spring-core: 6.1.2 → 6.1.3
WebAuthn4J Spring Security Improper signature counter value handling
WebAuthn4J Spring Security Improper signature counter value handling
com.webauthn4j:webauthn4j-spring-security-core: before 0.9.1.RELEASE
VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability
https://tanzu.vmware.com/security/cve-2022-22963; https://nvd.nist.gov/vuln/detail/CVE-2022-22963
Pivotal Spring Framework contains unsafe Java deserialization methods
Pivotal Spring Framework contains unsafe Java deserialization methods
org.springframework:spring-web: before 6.0.0
VMware Spring Cloud Gateway Code Injection Vulnerability
https://nvd.nist.gov/vuln/detail/CVE-2022-22947
Spring Framework JDK 9+ Remote Code Execution Vulnerability
https://nvd.nist.gov/vuln/detail/CVE-2022-22965
VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability
https://nvd.nist.gov/vuln/detail/CVE-2020-5410
VMware Tanzu Spring Data Commons Property Binder Vulnerability
https://nvd.nist.gov/vuln/detail/CVE-2018-1273
RFD attack via Content-Disposition header sourced from request input by Spring MVC or Spring WebFlux Application
RFD attack via Content-Disposition header sourced from request input by Spring MVC or Spring WebFlux Application
org.springframework:spring-webmvc: 5.2.0.RELEASE → 5.2.3.RELEASE
Tooling for Spring
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.