Spring By Vmware Spring Security vulnerabilities
2 known vulnerabilities affecting spring_by_vmware/spring_security.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2020-5408MEDIUMCVSS 6.5≥ 4.2, < 4.2.16≥ 5.0, < 5.0.16+3 more2020-05-14
CVE-2020-5408 [MEDIUM] CWE-329 CVE-2020-5408: Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x pr
Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of the queryable text encryptor. A malicious user with access to the data that has been encrypted using such an encryptor may be able to d
cvelistv5nvd
CVE-2020-5407HIGHCVSS 8.8≥ 5.2, < 5.2.4≥ 5.3, < 5.3.22020-05-13
CVE-2020-5407 [HIGH] CWE-347 CVE-2020-5407: Spring Security versions 5.2.x prior to 5.2.4 and 5.3.x prior to 5.3.2 contain a signature wrapping
Spring Security versions 5.2.x prior to 5.2.4 and 5.3.x prior to 5.3.2 contain a signature wrapping vulnerability during SAML response validation. When using the spring-security-saml2-service-provider component, a malicious user can carefully modify an otherwise valid SAML response and append an arbitrary assertion that Spring Security will accept as val
cvelistv5nvd