cbcvebase.
CVE-2022-31679
published 2022-09-21

CVE-2022-31679: Applications that allow HTTP PATCH access to resources exposed by Spring Data REST in versions 3.6.0 - 3.5.5, 3.7.0 - 3.7.2, and older unsupported versions, if…

PriorityP414low3.7CVSS 3.1
AVNACHPRNUINSUCLINAN
EPSS
0.47%
37.4th percentile
Applications that allow HTTP PATCH access to resources exposed by Spring Data REST in versions 3.6.0 - 3.5.5, 3.7.0 - 3.7.2, and older unsupported versions, if an attacker knows about the structure of the underlying domain model, they can craft HTTP requests that expose hidden entity attributes.

Affected

3 ranges
VendorProductVersion rangeFixed in
vmwarespring_data_rest
vmwarespring_data_rest>= 3.6.0 < 3.6.73.6.7
vmwarespring_data_rest>= 3.7.0 < 3.7.33.7.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.