Known Vulnerabilities for Spring Framework by Vmware
Listed below are 10 of the newest known vulnerabilities associated with "Spring Framework" by "Vmware".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2024-22233 json | 7.5 - HIGH | 2024-01-22 | 2024-01-29 | |
| CVE-2023-44794 json | An issue in Dromara SaToken version 1.36.0 and before allows a remote attacker to escalate privileges via a crafted payload t... | 9.8 - CRITICAL | 2023-10-25 | 2023-10-31 |
| CVE-2023-34053 json | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... | 7.5 - HIGH | 2023-11-28 | 2023-12-04 |
| CVE-2023-20863 json | In spring framework versions prior to 5.2.24 release+ ,5.3.27+ and 6.0.8+ , it is possible for a user to provide a specially ... | 6.5 - MEDIUM | 2023-04-13 | 2023-04-21 |
| CVE-2023-20861 json | In Spring Framework versions 6.0.0 - 6.0.6, 5.3.0 - 5.3.25, 5.2.0.RELEASE - 5.2.22.RELEASE, and older unsupported versions, i... | 6.5 - MEDIUM | 2023-03-23 | 2023-04-20 |
| CVE-2023-20860 json | Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration wit... | 7.5 - HIGH | 2023-03-27 | 2023-05-05 |
| CVE-2022-22971 json | In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, application with a STOMP over WebSocket... | 6.5 - MEDIUM | 2022-05-12 | 2022-10-05 |
| CVE-2022-22970 json | In spring framework versions prior to 5.3.20+ , 5.2.22+ and old unsupported versions, applications that handle file uploads a... | 5.3 - MEDIUM | 2022-05-12 | 2022-10-07 |
| CVE-2022-22968 json | In Spring Framework versions 5.3.0 - 5.3.18, 5.2.0 - 5.2.20, and older unsupported versions, the patterns for disallowedField... | 5.3 - MEDIUM | 2022-04-14 | 2022-10-19 |
| CVE-2022-22965 json | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data bindin... | 9.8 - CRITICAL | 2022-04-01 | 2023-02-09 |