Package impact
Maven / org.springframework.security:spring-security-core
| CVE | Severity | CVSS | Risk | Published | Description | Impact |
|---|---|---|---|---|---|---|
| CVE-2011-2894 | medium | — | 6.8 | 15y ago | Spring Framework and Spring Security vulnerable to Deserialization of Untrusted Data | |
| CVE-2011-2731 | medium | — | 5.1 | 14y ago | Concurrent Execution using Shared Resource with Improper Synchronization in Spring Security | |
| CVE-2012-5055 | medium | — | 5.0 | 14y ago | Exposure of Sensitive Information to an Unauthorized Actor in Spring Security | |
| CVE-2010-3700 | medium | — | 5.0 | 16y ago | Authentication Bypass Using an Alternate Path or Channel in SpringSource Spring Security and Acegi Security | |
| CVE-2026-22751 | medium | 4.8 | 4.8 | 1mo ago | Spring Security Core has a TOCTOU race condition when One-Time Token login with JdbcOneTimeTokenService is configured | |
| CVE-2011-2732 | medium | — | 4.3 | 14y ago | Improper Control of Generation of Code in Spring Security |