Pivotal Software

Spring Framework

11 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 48.23%
  • Published 23.02.2024 05:15:08
  • Last modified 13.02.2025 18:16:47

Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/6...

  • EPSS 0.34%
  • Published 10.01.2020 14:15:10
  • Last modified 21.11.2024 01:59:12

The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape certain characters, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a...

  • EPSS 0.23%
  • Published 25.05.2017 17:29:00
  • Last modified 20.04.2025 01:37:25

When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration. This enabled an XXE attack.

  • EPSS 0.29%
  • Published 25.05.2017 17:29:00
  • Last modified 20.04.2025 01:37:25

Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mappings for authorization and for mapping requests to controllers respectively. Differences in the strictness of the pattern matching me...

  • EPSS 4.93%
  • Published 29.12.2016 09:59:00
  • Last modified 12.04.2025 10:46:40

An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traversal attacks.

  • EPSS 1.38%
  • Published 12.07.2016 19:59:00
  • Last modified 12.04.2025 10:46:40

Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory errors) vi...

  • EPSS 0.29%
  • Published 10.03.2015 14:59:04
  • Last modified 12.04.2025 10:46:40

The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.

  • EPSS 5.83%
  • Published 19.02.2015 20:59:00
  • Last modified 12.04.2025 10:46:40

Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.

  • EPSS 18.93%
  • Published 20.11.2014 17:50:00
  • Last modified 12.04.2025 10:46:40

Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related to static resource handling.

  • EPSS 2.2%
  • Published 20.03.2014 16:55:12
  • Last modified 12.04.2025 10:46:40

Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the requested URI in a defau...