CVE-2026-47849
- EPSS 0.27%
- Veröffentlicht 27.08.2026 06:17:16
- Zuletzt bearbeitet 02.09.2026 15:47:11
Spring Data REST does not guard identifier (@Id) and version (@Version) properties against mutation via RFC 6902 JSON Patch (application/json-patch+json) requests. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - 4.5.12 ...
CVE-2026-47850
- EPSS 0.18%
- Veröffentlicht 26.08.2026 23:28:40
- Zuletzt bearbeitet 04.09.2026 20:07:16
Spring Data REST does not preserve the persisted version (@Version) property of an aggregate root when handling an HTTP PUT against an immutable target type. Spring Data REST 5.1.0 Spring Data REST 5.0.0 - 5.0.6 Spring Data REST 4.5.0 - 4.5.12 Spring...
CVE-2026-41837
- EPSS 0.19%
- Veröffentlicht 09.06.2026 23:49:49
- Zuletzt bearbeitet 23.07.2026 09:10:00
Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson customizations before handing them to Querydsl. Affected versions: Spring Data REST 3.7.0 through 3.7....
CVE-2026-41730
- EPSS 0.2%
- Veröffentlicht 09.06.2026 23:49:21
- Zuletzt bearbeitet 23.07.2026 09:10:00
Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persistence-layer internals to HTTP clients. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4.3.0 through 4.3.16; 4.4.0 throu...
CVE-2026-41729
- EPSS 0.39%
- Veröffentlicht 09.06.2026 23:49:17
- Zuletzt bearbeitet 23.07.2026 09:10:00
Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests. When a persistent entity exposes a Map-typed property, the JSON Pointer path segment used as t...
CVE-2026-41728
- EPSS 0.31%
- Veröffentlicht 09.06.2026 23:49:13
- Zuletzt bearbeitet 23.07.2026 09:10:00
Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer. Affected versions: Spring Data REST 3.7.0 through 3.7.19; 4....
CVE-2022-31679
- EPSS 0.49%
- Veröffentlicht 21.09.2022 18:15:10
- Zuletzt bearbeitet 22.05.2025 19:15:31
Applications that allow HTTP PATCH access to resources exposed by Spring Data REST in versions 3.6.0 - 3.5.5, 3.7.0 - 3.7.2, and older unsupported versions, if an attacker knows about the structure of the underlying domain model, they can craft HTTP ...
CVE-2021-22047
- EPSS 0.75%
- Veröffentlicht 28.10.2021 16:15:07
- Zuletzt bearbeitet 21.11.2024 05:49:29
In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally exposed under U...
CVE-2018-1259
- EPSS 5.01%
- Veröffentlicht 11.05.2018 20:29:00
- Zuletzt bearbeitet 26.06.2026 18:44:14
Spring Data Commons, versions 1.13 prior to 1.13.12 and 2.0 prior to 2.0.7, used in combination with XMLBeam 1.4.14 or earlier versions, contains a property binder vulnerability caused by improper restriction of XML external entity references as unde...
CVE-2018-1274
- EPSS 1.97%
- Veröffentlicht 18.04.2018 16:29:00
- Zuletzt bearbeitet 26.06.2026 18:44:14
Spring Data Commons, versions 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property path parser vulnerability caused by unlimited resource allocation. An unauthenticated remote malicious user (or attacker) can issue reques...