CVE-2023-34055
- EPSS 0.28%
- Veröffentlicht 28.11.2023 09:15:07
- Zuletzt bearbeitet 13.02.2025 17:16:34
In Spring Boot versions 2.7.0 - 2.7.17, 3.0.0-3.0.12 and 3.1.0-3.1.5, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the...
CVE-2023-20883
- EPSS 0.4%
- Veröffentlicht 26.05.2023 17:15:14
- Zuletzt bearbeitet 16.01.2025 15:15:10
In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there is potential for a denial-of-service (DoS) attack if Spring MVC is used together with a reverse proxy cache.
CVE-2023-20873
- EPSS 0.39%
- Veröffentlicht 20.04.2023 21:15:08
- Zuletzt bearbeitet 05.05.2025 16:15:29
In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susceptible to a security bypass. Users of affected versions should apply the following mitigation: 3.0.x...
CVE-2023-22602
- EPSS 0.14%
- Veröffentlicht 14.01.2023 10:15:09
- Zuletzt bearbeitet 21.11.2024 07:45:02
When using Apache Shiro before 1.11.0 together with Spring Boot 2.6+, a specially crafted HTTP request may cause an authentication bypass. The authentication bypass occurs when Shiro and Spring Boot are using different pattern-matching techniques. B...
CVE-2022-27772
- EPSS 0.83%
- Veröffentlicht 30.03.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 06:56:09
spring-boot versions prior to version v2.2.11.RELEASE was vulnerable to temporary directory hijacking. This vulnerability impacted the org.springframework.boot.web.server.AbstractConfigurableWebServerFactory.createTempDir method. NOTE: This vulnerabi...
CVE-2021-26987
- EPSS 1.87%
- Veröffentlicht 15.03.2021 22:15:13
- Zuletzt bearbeitet 21.11.2024 05:57:08
Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability which when successfully exploited could lead to Remote Code Execution. All versions of Element Plug-...
CVE-2018-1196
- EPSS 0.6%
- Veröffentlicht 19.03.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:22
Spring Boot supports an embedded launch script that can be used to easily run the application as a systemd or init.d linux service. The script included with Spring Boot 1.5.9 and earlier and 2.0.0.M1 through 2.0.0.M7 is susceptible to a symlink attac...
CVE-2017-8046
- EPSS 93.73%
- Veröffentlicht 04.01.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 03:33:12
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java co...