8
CVE-2026-47873
- EPSS 0.18%
- Veröffentlicht 30.07.2026 06:25:52
- Zuletzt bearbeitet 30.09.2026 18:38:43
- Erkennungen
Spring Tools Docker integration publishes unauthenticated debug (JDWP) and JMX ports on all network interfaces
The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Broadcom ≫ Spring Tools SwPlatform eclipse Version < 5.3.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.083 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| VMware | 8 | 2.1 | 5.9 |
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-1327 Binding to an Unrestricted IP Address
The product assigns the address 0.0.0.0 for a database server, a cloud service/instance, or any computing resource that communicates remotely.
https://spring.io/security/cve-2026-47873