CVEs (10)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Pivotal Software 1Spring Framework Nov 21, 2024 Jan 10, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape certain characters, which allows remote attackers to conduct cross-site...Show more |
2Pivotal Software Vmware3Spring Framework Spring FrameworkSpring SecurityMay 13, 2026 May 25, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mappings for authorization and for mapping requests to controllers respectively. Differences in the strictn...Show more |
2Pivotal Software Vmware2Spring Framework Spring FrameworkMay 13, 2026 May 25, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolution of URI references in a DTD declaration...Show more |
2Pivotal Software Vmware2Spring Framework Spring FrameworkMay 6, 2026 Dec 29, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and as a result exposed to directory traver...Show more |
3Fedoraproject Pivotal SoftwareVmware3Fedora Spring FrameworkSpring FrameworkMay 6, 2026 Jul 12, 2016 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumptio...Show more |
2Pivotal Software Vmware2Spring Framework Spring FrameworkMay 6, 2026 Mar 10, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors. |
Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL. |
2Pivotal Software Vmware2Spring Framework Spring FrameworkMay 6, 2026 Nov 20, 2014 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrary files via unspecified vectors, related...Show more |
Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers to inject arbitrary web script or HTML vi...Show more |
2Pivotal Software Vmware2Spring Framework Spring FrameworkApr 29, 2026 Jan 26, 2014 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a den...Show more |