Known Vulnerabilities for Spring Security by VMware
Listed below are 10 of the newest known vulnerabilities associated with "Spring Security" by "VMware".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-22732 | When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that... | Not Provided | 2026-03-19 | 2026-04-02 |
| CVE-2022-22978 | In spring security versions prior to 5.4.11+, 5.5.7+ , 5.6.4+ and older unsupported versions, RegexRequestMatcher can easily ... | 9.8 - CRITICAL | 2022-05-19 | 2023-04-11 |
| CVE-2022-22976 | Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer over... | 5.3 - MEDIUM | 2022-05-19 | 2023-02-03 |
| CVE-2021-22119 | Spring Security versions 5.5.x prior to 5.5.1, 5.4.x prior to 5.4.7, 5.3.x prior to 5.3.10 and 5.2.x prior to 5.2.11 are susc... | 7.5 - HIGH | 2021-06-29 | 2023-11-07 |
| CVE-2021-22112 | Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versi... | 8.8 - HIGH | 2021-02-23 | 2023-11-07 |
| CVE-2020-5408 | Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x p... | 6.5 - MEDIUM | 2020-05-14 | 2021-06-14 |
| CVE-2019-11272 | Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPass... | 7.3 - HIGH | 2019-06-26 | 2021-06-08 |
| CVE-2019-3795 | Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomnes... | 5.3 - MEDIUM | 2019-04-09 | 2021-11-02 |
| CVE-2018-1199 | Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.3.x b... | 5.3 - MEDIUM | 2018-03-16 | 2023-11-07 |
| CVE-2017-4995 | An issue was discovered in Pivotal Spring Security 4.2.0.RELEASE through 4.2.2.RELEASE, and Spring Security 5.0.0.M1. When co... | 8.1 - HIGH | 2017-11-27 | 2023-11-07 |