Known Vulnerabilities for Spring Boot by Vmware
Listed below are 10 of the newest known vulnerabilities associated with "Spring Boot" by "Vmware".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-22731 json | Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endp... | Not Provided | 2026-03-19 | 2026-03-20 |
| CVE-2023-44794 json | An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload t... | 9.8 - CRITICAL | 2023-10-25 | 2023-10-31 |
| CVE-2023-34055 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 6.5 - MEDIUM | 2023-11-28 | 2023-12-04 |
| CVE-2023-22602 json | When using Apache Shiro before 1.11.0 together with Spring Boot 2.6+, a specially crafted HTTP request may cause an authentic... | 7.5 - HIGH | 2023-01-14 | 2023-11-07 |
| CVE-2023-20883 json | In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there i... | 7.5 - HIGH | 2023-05-26 | 2023-07-03 |
| CVE-2023-20873 json | In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Clo... | 9.8 - CRITICAL | 2023-04-20 | 2023-08-28 |
| CVE-2022-27772 json | ** UNSUPPORTED WHEN ASSIGNED ** spring-boot versions prior to version v2.2.11.RELEASE was vulnerable to temporary directory h... | 7.8 - HIGH | 2022-03-30 | 2023-11-07 |
| CVE-2021-26987 json | Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are suscep... | 9.8 - CRITICAL | 2021-03-15 | 2022-04-07 |
| CVE-2018-1196 json | Spring Boot supports an embedded launch script that can be used to easily run the application as a systemd or init.d linux se... | 5.9 - MEDIUM | 2018-03-19 | 2022-04-07 |
| CVE-2017-8046 json | Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to... | 9.8 - CRITICAL | 2018-01-04 | 2022-04-07 |