Package impact

java Maven / org.springframework:spring-core

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2015-5211 critical 9.6 9.6 9y ago Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves… debianjavavmware
CVE-2016-5007 high 7.5 7.5 9y ago Spring Security and Spring Framework may not recognize certain paths that should be protected debianjavavmware
CVE-2011-2730 high 7.5 14y ago Improper Neutralization of Directives in Dynamically Evaluated Code in Spring Framework java
CVE-2011-2894 medium 6.8 15y ago Spring Framework and Spring Security vulnerable to Deserialization of Untrusted Data javavmware
CVE-2015-0201 medium 5.0 11y ago Moderate severity vulnerability that affects org.springframework:spring-core debianjavavmware
CVE-2014-3578 medium 5.0 11y ago Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL. debianjava
CVE-2025-41249 unknown 8mo ago The Spring Framework annotation detection mechanism may not correctly resolve annotations on methods within type hierarchies with a parameterized super type with unbounded generics. This can be an is… debianjava
CVE-2024-22233 unknown 2y ago In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application i… debianjava
CVE-2021-22096 unknown 4y ago In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. debianjava
CVE-2009-1190 unknown 4y ago Spring Framework Inefficient Regular Expression Complexity java
CVE-2021-22060 unknown 4y ago Log entry injection in Spring Framework debianjava
CVE-2018-15756 unknown 6y ago Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving stati… debianjava
CVE-2018-1272 unknown 8y ago Possible privilege escalation in org.springframework:spring-core debianjava
CVE-2018-1271 unknown 8y ago Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, imag… debianjava
CVE-2018-1258 unknown 8y ago Spring Framework when used in combination with any versions of Spring Security contains an authorization bypass java
CVE-2018-1257 unknown 8y ago Spring Framework, versions 5.0.x prior to 5.0.6, versions 4.3.x prior to 4.3.17, and older unsupported versions allows applications to expose STOMP over WebSocket endpoints with a simple, in-memory S… debianjava
CVE-2018-1199 unknown 8y ago Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.3.x before 4.3.14 and 5.0.x before 5.0.3) does not consider URL path parameters… debianjava
CVE-2018-11040 unknown 8y ago Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through… debianjava