Pivotal / Spring Framework
11 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2024-22243 | CVE-2024-22243: Spring Framework URL Parsing with Host Validation | HIGH | 8.1 | Feb 23, 2024 |
| CVE-2013-6430 | Framework: org.spring.web.util.JavaScriptUtils.javaScriptEscape insufficient escaping of characters | MEDIUM | 5.4 | Jan 10, 2020 |
| CVE-2018-15756 | DoS Attack via Range Requests | HIGH | 7.5 | Oct 18, 2018 |
| CVE-2018-11040 | springframework: cross-domain requests via JSONP through AbstractJsonpResponseBodyAdvice | HIGH | 7.5 | Jun 25, 2018 |
| CVE-2018-11039 | springframework: Cross Site Tracing (XST) if vulnerable to XSS | MEDIUM | 5.9 | Jun 25, 2018 |
| CVE-2018-1258 | spring-security-core: Unauthorized Access with Spring Security Method Security | HIGH | 8.8 | May 11, 2018 |
| CVE-2018-1257 | spring-framework: ReDoS Attack with spring-messaging | MEDIUM | 6.5 | May 11, 2018 |
| CVE-2016-5007 | spring: Path matching inconsistency | HIGH | 7.5 | May 25, 2017 |
| CVE-2014-0225 | Framework: Information disclosure via SSRF | HIGH | 8.8 | May 25, 2017 |
| CVE-2016-9878 | Framework: Directory Traversal in the Spring Framework ResourceServlet | HIGH | 7.5 | Dec 29, 2016 |
| CVE-2015-3192 | Framework: denial-of-service attack with XML input | MEDIUM | 5.5 | Jul 12, 2016 |
| CVE-2015-0201 | The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to othe… | MEDIUM | 5.0 | Mar 10, 2015 |
| CVE-2014-3578 | Framework: Directory traversal | MEDIUM | 5.0 | Feb 19, 2015 |
| CVE-2014-3625 | Framework: directory traversal flaw | MEDIUM | 5.0 | Nov 20, 2014 |
| CVE-2014-1904 | Framework: cross-site scripting flaw when using Spring MVC | MEDIUM | 4.3 | Mar 20, 2014 |
| CVE-2013-6429 | Framework: XML External Entity (XXE) injection flaw | MEDIUM | 6.8 | Jan 26, 2014 |
Showing 1 to 11 of 11 CVEs