Spring Framework
Pivotal · 11 CVEs
CVE-2024-22243: Spring Framework URL Parsing with Host Validation
Feb 23, 2024
Framework: org.spring.web.util.JavaScriptUtils.javaScriptEscape insufficient escaping of characters
Jan 10, 2020
DoS Attack via Range Requests
Oct 18, 2018
springframework: cross-domain requests via JSONP through AbstractJsonpResponseBodyAdvice
Jun 25, 2018
springframework: Cross Site Tracing (XST) if vulnerable to XSS
Jun 25, 2018
spring-security-core: Unauthorized Access with Spring Security Method Security
May 11, 2018
spring-framework: ReDoS Attack with spring-messaging
May 11, 2018
spring: Path matching inconsistency
May 25, 2017
Framework: Information disclosure via SSRF
May 25, 2017
Framework: Directory Traversal in the Spring Framework ResourceServlet
Dec 29, 2016
Framework: denial-of-service attack with XML input
Jul 12, 2016
The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows r…
Mar 10, 2015
Framework: Directory traversal
Feb 19, 2015
Framework: directory traversal flaw
Nov 20, 2014
Framework: cross-site scripting flaw when using Spring MVC
Mar 20, 2014
Framework: XML External Entity (XXE) injection flaw
Jan 26, 2014
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2024-22243 | CVE-2024-22243: Spring Framework URL Parsing with Host Validation | HIGH | 3.97% | Feb 23, 2024 |
| CVE-2013-6430 | Framework: org.spring.web.util.JavaScriptUtils.javaScriptEscape insufficient escaping of characters | MEDIUM | 1.77% | Jan 10, 2020 |
| CVE-2018-15756 | DoS Attack via Range Requests | HIGH | 9.21% | Oct 18, 2018 |
| CVE-2018-11040 | springframework: cross-domain requests via JSONP through AbstractJsonpResponseBodyAdvice | HIGH | 3.23% | Jun 25, 2018 |
| CVE-2018-11039 | springframework: Cross Site Tracing (XST) if vulnerable to XSS | MEDIUM | 2.75% | Jun 25, 2018 |
| CVE-2018-1258 | spring-security-core: Unauthorized Access with Spring Security Method Security | HIGH | 2.46% | May 11, 2018 |
| CVE-2018-1257 | spring-framework: ReDoS Attack with spring-messaging | MEDIUM | 3.04% | May 11, 2018 |
| CVE-2016-5007 | spring: Path matching inconsistency | HIGH | 2.92% | May 25, 2017 |
| CVE-2014-0225 | Framework: Information disclosure via SSRF | HIGH | 1.70% | May 25, 2017 |
| CVE-2016-9878 | Framework: Directory Traversal in the Spring Framework ResourceServlet | HIGH | 5.75% | Dec 29, 2016 |
| CVE-2015-3192 | Framework: denial-of-service attack with XML input | MEDIUM | 2.56% | Jul 12, 2016 |
| CVE-2015-0201 | The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to othe… | MEDIUM | 1.90% | Mar 10, 2015 |
| CVE-2014-3578 | Framework: Directory traversal | MEDIUM | 6.33% | Feb 19, 2015 |
| CVE-2014-3625 | Framework: directory traversal flaw | MEDIUM | 10.32% | Nov 20, 2014 |
| CVE-2014-1904 | Framework: cross-site scripting flaw when using Spring MVC | MEDIUM | 6.90% | Mar 20, 2014 |
| CVE-2013-6429 | Framework: XML External Entity (XXE) injection flaw | MEDIUM | 90.56% | Jan 26, 2014 |
Showing 1 to 11 of 11 CVEs