Known Vulnerabilities for Spring Session by Vmware
Listed below are 1 of the newest known vulnerabilities associated with "Spring Session" by "Vmware".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-41839 json | A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerable to... | Not Provided | 2026-06-09 | 2026-06-23 |
| CVE-2026-40973 json | A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. ... | Not Provided | 2026-04-28 | 2026-04-29 |
| CVE-2023-20866 json | In Spring Session version 3.0.0, the session id can be logged to the standard output stream. This vulnerability exposes sensi... | 6.5 - MEDIUM | 2023-04-13 | 2023-04-21 |