CVE-2018-1270
- EPSS 89.95%
- Veröffentlicht 06.04.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:30
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A ma...
CVE-2018-1272
- EPSS 2.17%
- Veröffentlicht 06.04.2018 13:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:30
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a r...
CVE-2018-1199
- EPSS 0.85%
- Veröffentlicht 16.03.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:22
Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.3.x before 4.3.14 and 5.0.x before 5.0.3) does not consider URL path parameters when processing security constraints. By adding a ...
CVE-2016-5007
- EPSS 0.16%
- Veröffentlicht 25.05.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mappings for authorization and for mapping requests to controllers respectively. Differences in the strictness of the pattern matching me...
CVE-2015-5211
- EPSS 1.92%
- Veröffentlicht 25.05.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch scrip...
CVE-2014-0225
- EPSS 0.24%
- Veröffentlicht 25.05.2017 17:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.
CVE-2016-9878
- EPSS 4.93%
- Veröffentlicht 29.12.2016 09:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.
CVE-2015-3192
- EPSS 1.38%
- Veröffentlicht 12.07.2016 19:59:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) vi...
- EPSS 0.18%
- Veröffentlicht 10.03.2015 14:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.
- EPSS 16.99%
- Veröffentlicht 20.11.2014 17:50:00
- Zuletzt bearbeitet 06.05.2026 22:30:45
Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.