VMware

Spring Boot

20 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.09%
  • Veröffentlicht 11.06.2026 05:04:28
  • Zuletzt bearbeitet 04.09.2026 18:13:58

Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can pre-create this predictable directory or p...

  • EPSS 0.12%
  • Veröffentlicht 11.06.2026 05:03:53
  • Zuletzt bearbeitet 04.09.2026 18:05:38

Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail property, such as spring.mail.properties.mail.smtp.ssl.checkserveridentity=true, are not affected. Affected versions: Spring Boo...

  • EPSS 0.11%
  • Veröffentlicht 27.04.2026 23:36:06
  • Zuletzt bearbeitet 24.07.2026 21:10:00

When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one file on the host each time the application is started. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), ...

  • EPSS 0.49%
  • Veröffentlicht 27.04.2026 23:34:51
  • Zuletzt bearbeitet 24.07.2026 21:10:00

In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its ...

  • EPSS 0.31%
  • Veröffentlicht 27.04.2026 23:32:58
  • Zuletzt bearbeitet 24.07.2026 21:10:00

Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they are numeric values with a predictable range. Affected: Spring Boot 4.0....

  • EPSS 0.18%
  • Veröffentlicht 27.04.2026 23:31:40
  • Zuletzt bearbeitet 24.07.2026 21:10:00

Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fi...

  • EPSS 0.14%
  • Veröffentlicht 27.04.2026 23:29:51
  • Zuletzt bearbeitet 24.07.2026 21:10:00

A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `true` and the attack persists across application restarts, this may allow...

  • EPSS 0.26%
  • Veröffentlicht 27.04.2026 23:15:19
  • Zuletzt bearbeitet 24.07.2026 21:10:00

An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the attacker determining the secret and uploading changed ...

  • EPSS 0.16%
  • Veröffentlicht 27.04.2026 22:45:13
  • Zuletzt bearbeitet 24.07.2026 21:10:00

When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14) per vendor adviso...

  • EPSS 0.14%
  • Veröffentlicht 27.04.2026 19:16:52
  • Zuletzt bearbeitet 14.05.2026 16:09:59

When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the Elasticsearch server. Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory...