cbcvebase.

Vmware Spring Boot vulnerabilities

18 known vulnerabilities affecting vmware/spring_boot.

Total CVEs
18
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL6HIGH8MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2017-8046P1CRITICALCVSS 9.8ExploitedPoCRansomwarefixed in 1.5.9v2.0.0-milestone1+4 more2018-01-04
CVE-2017-8046 [CRITICAL] CWE-20 CVE-2017-8046: Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingall Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.
nvd
CVE-2021-26987P2CRITICALCVSS 9.8fixed in 1.3.22021-03-15
CVE-2021-26987 [CRITICAL] CVE-2021-26987: Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions Element Plug-in for vCenter Server incorporates SpringBoot Framework. SpringBoot Framework versions prior to 1.3.2 are susceptible to a vulnerability which when successfully exploited could lead to Remote Code Execution. All versions of Element Plug-in for vCenter Server, Management Services versions prior to 2.17.56 and Management Node versions through 12
nvd
CVE-2026-40976P3CRITICALCVSS 9.1≥ 4.0.0, < 4.0.62026-04-28
CVE-2026-40976 [CRITICAL] CWE-862 CVE-2026-40976: In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized ac In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default web security filter chain; depend on spring-boot-actuator-autoconfigure
nvd
CVE-2026-22731P3HIGHCVSS 8.1≥ 3.4.0, < 3.4.15≥ 3.5.0, < 3.5.12+1 more2026-03-19
CVE-2026-22731 [HIGH] CWE-288 CVE-2026-22731: Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under a specific path, already configured for a Health Group additional path. This issue affects Spring Boot: from 4.0 before 4.0.3, from 3.5 before 3.5.11, from 3.4 before 3.4.15. T
nvd
CVE-2026-22733P3HIGHCVSS 8.1fixed in 2.7.32≥ 3.3.0, < 3.3.18+3 more2026-03-20
CVE-2026-22733 [HIGH] CWE-288 CVE-2026-22733: Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability Spring Boot applications with Actuator can be vulnerable to an "Authentication Bypass" vulnerability when an application endpoint that requires authentication is declared under the path used by the CloudFoundry Actuator endpoints. This issue affects Spring Security: from 4.0.0 through 4.0.3, from 3.5.0 through 3.5.11, from 3.4.0 through 3.4.14, from 3
nvd
CVE-2023-20873P3CRITICALCVSS 9.8fixed in 2.5.15≥ 2.6.0, < 2.6.14+3 more2023-04-20
CVE-2023-20873 [CRITICAL] CVE-2023-20873: In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an applicatio In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susceptible to a security bypass. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.6+. 2.7.x users should upgrade to 2.7.11+. Users of older, unsupported version
nvd
CVE-2026-40974P3CRITICALCVSS 9.8≥ 2.7.0, < 2.7.33≥ 3.3.0, < 3.3.19+3 more2026-04-28
CVE-2026-40974 [CRITICAL] CWE-295 CVE-2026-40974: Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); Cassandra SSL auto-configuration. Versions that are no longer
nvd
CVE-2023-22602P3HIGHCVSS 7.5v2.6.02023-01-14
CVE-2023-22602 [HIGH] CWE-436 CVE-2023-22602: When using Apache Shiro before 1.11.0 together with Spring Boot 2.6+, a specially crafted HTTP reque When using Apache Shiro before 1.11.0 together with Spring Boot 2.6+, a specially crafted HTTP request may cause an authentication bypass. The authentication bypass occurs when Shiro and Spring Boot are using different pattern-matching techniques. Both Shiro and Spring Boot < 2.6 default to Ant style pattern matching. Mitigation: Update to Apache Shi
nvd
CVE-2026-40971P3CRITICALCVSS 9.1≥ 3.5.0, < 3.5.14≥ 4.0.0, < 4.0.62026-04-27
CVE-2026-40971 [CRITICAL] CWE-295 CVE-2026-40971: When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hos When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14) per vendor advisory.
nvd
CVE-2026-40972P3HIGHCVSS 7.5fixed in 2.7.33≥ 3.3.0, < 3.3.19+3 more2026-04-28
CVE-2026-40972 [HIGH] CWE-208 CVE-2026-40972: An attacker on the same network as the remote application may be able to utilize a timing attack to An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the attacker determining the secret and uploading changed classes, thereby achieving remote code execution in the remote application. Affected: Spring Boot 4.0.0
nvd
CVE-2026-40975P3HIGHCVSS 7.5fixed in 2.7.33≥ 3.3.0, < 3.3.19+3 more2026-04-28
CVE-2026-40975 [HIGH] CWE-330 CVE-2026-40975: Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affect Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they are numeric values with a predictable range. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2
nvd
CVE-2022-27772P3HIGHCVSS 7.8fixed in 2.2.112022-03-30
CVE-2022-27772 [HIGH] CWE-668 CVE-2022-27772: spring-boot versions prior to version v2.2.11.RELEASE was vulnerable to temporary directory hijackin spring-boot versions prior to version v2.2.11.RELEASE was vulnerable to temporary directory hijacking. This vulnerability impacted the org.springframework.boot.web.server.AbstractConfigurableWebServerFactory.createTempDir method. NOTE: This vulnerability only affects products and/or versions that are no longer supported by the maintainer
nvd
CVE-2023-20883P3HIGHCVSS 7.5fixed in 2.5.14≥ 2.6.0, ≤ 2.6.14+3 more2023-05-26
CVE-2023-20883 [HIGH] CWE-400 CVE-2023-20883: In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsu In Spring Boot versions 3.0.0 - 3.0.6, 2.7.0 - 2.7.11, 2.6.0 - 2.6.14, 2.5.0 - 2.5.14 and older unsupported versions, there is potential for a denial-of-service (DoS) attack if Spring MVC is used together with a reverse proxy cache.
nvd
CVE-2026-40973P3HIGHCVSS 7.0fixed in 2.7.33≥ 3.3.0, < 3.3.19+3 more2026-04-28
CVE-2026-40973 [HIGH] CWE-377 CVE-2026-40973: A local attacker on the same host as the application may be able to take control of the directory us A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `true` and the attack persists across application restarts, this may allow the attacker to read session information and hijack authenticated users or deploy a gadget chain and e
nvd
CVE-2026-40977P4MEDIUMCVSS 6.7fixed in 2.7.33≥ 3.3.0, < 3.3.19+3 more2026-04-28
CVE-2026-40977 [MEDIUM] CWE-59 CVE-2026-40977: When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write acc When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one file on the host each time the application is started. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7
nvd
CVE-2023-34055P4MEDIUMCVSS 6.5≥ 2.7.0, ≤ 2.7.17≥ 3.0.0, ≤ 3.0.12+1 more2023-11-28
CVE-2023-34055 [MEDIUM] CVE-2023-34055: In Spring Boot versions 2.7.0 - 2.7.17, 3.0.0-3.0.12 and 3.1.0-3.1.5, it is possible for a user to p In Spring Boot versions 2.7.0 - 2.7.17, 3.0.0-3.0.12 and 3.1.0-3.1.5, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition. Specifically, an application is vulnerable when all of the following are true: * the application uses Spring MVC or Spring WebFlux * org.springframework.boot:spring-b
nvd
CVE-2026-40970P4MEDIUMCVSS 6.8≥ 4.0.0, < 4.0.62026-04-27
CVE-2026-40970 [MEDIUM] CWE-295 CVE-2026-40970: When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perfor When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the Elasticsearch server. Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.
nvd
CVE-2018-1196P4MEDIUMCVSS 5.9≤ 1.5.9v2.0.02018-03-19
CVE-2018-1196 [MEDIUM] CWE-59 CVE-2018-1196: Spring Boot supports an embedded launch script that can be used to easily run the application as a s Spring Boot supports an embedded launch script that can be used to easily run the application as a systemd or init.d linux service. The script included with Spring Boot 1.5.9 and earlier and 2.0.0.M1 through 2.0.0.M7 is susceptible to a symlink attack which allows the "run_user" to overwrite and take ownership of any file on the same system. In order t
nvd
Vmware Spring Boot vulnerabilities | cvebase