Vmware Spring Framework vulnerabilities
70 known vulnerabilities affecting vmware/spring_framework.
Total CVEs
70
CISA KEV
1
actively exploited
Public exploits
3
Exploited in wild
1
Severity breakdown
CRITICAL6HIGH21MEDIUM41LOW2
Vulnerabilities
Page 1 of 4
CVE-2022-22965P1CRITICALCVSS 9.8KEVPoCRansomwarefixed in 5.2.20≥ 5.3.0, < 5.3.182022-04-01
CVE-2022-22965 [CRITICAL] CWE-94 CVE-2022-22965: A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execut
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature
nvd
CVE-2018-1270P2CRITICALCVSS 9.8fixed in 4.3.16≥ 5.0.0, < 5.0.52018-04-06
CVE-2018-1270 [CRITICAL] CWE-94 CVE-2018-1270: Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution
nvd
CVE-2018-1275P2CRITICALCVSS 9.8≥ 4.3.0, < 4.3.16≥ 5.0.0, < 5.0.52018-04-11
CVE-2018-1275 [CRITICAL] CVE-2018-1275: Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.
nvd
CVE-2018-1271P3MEDIUMCVSS 5.9PoC≥ 4.3.0, < 4.3.15≥ 5.0.0, < 5.0.52018-04-06
CVE-2018-1271 [MEDIUM] CWE-22 CVE-2018-1271: Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a reque
nvd
CVE-2020-5398P2HIGHCVSS 7.5≥ 5.0.0, < 5.0.16≥ 5.1.0, < 5.1.13+1 more2020-01-17
CVE-2020-5398 [HIGH] CWE-79 CVE-2020-5398: In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0
In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input.
nvd
CVE-2016-1000027P2CRITICALCVSS 9.8fixed in 6.0.02020-01-02
CVE-2016-1000027 [CRITICAL] CWE-502 CVE-2016-1000027: Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue i
Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intend
nvd
CVE-2013-6429P3MEDIUMCVSS 6.8v4.0.02014-01-26
CVE-2013-6429 [MEDIUM] CVE-2013-6429: The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue, and a different vulnerability than CVE-2013
nvd
CVE-2014-0054P3MEDIUMCVSS 6.8≤ 3.2.7v3.0.6+12 more2014-04-17
CVE-2014-0054 [MEDIUM] CVE-2014-0054: The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 be
The Jaxb2RootElementHttpMessageConverter in Spring MVC in Spring Framework before 3.2.8 and 4.0.0 before 4.0.2 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via crafted XML, aka an XML External Entity (XXE) issue. NOTE: this vulnerability exists because o
nvd
CVE-2025-41242P3MEDIUMCVSS 5.9PoC≥ 6.2.x, < 6.2.10≥ 6.1.x, < 6.1.22+1 more2025-08-18
CVE-2025-41242 [MEDIUM] CWE-22 CVE-2025-41242: Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deploye
Spring Framework MVC applications can be vulnerable to a “Path Traversal Vulnerability” when deployed on a non-compliant Servlet container.
An application can be vulnerable when all the following are true:
* the application is deployed as a WAR or with an embedded Servlet container
* the Servlet container does not reject suspicious sequences https:
nvd
CVE-2026-41855P3CRITICALCVSS 9.8≥ 5.3.0, < 5.3.49≥ 6.1.0, < 6.1.28+2 more2026-06-09
CVE-2026-41855 [CRITICAL] CWE-502 CVE-2026-41855: In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageCon
In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to unauthorized actions via gadget class deserialization.
Affected versions:
Spring Framework 7.0.0 through 7.0.7;
nvd
CVE-2018-1258P3HIGHCVSS 8.8v5.0.52018-05-11
CVE-2018-1258 [HIGH] CWE-863 CVE-2018-1258: Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contain
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
nvd
CVE-2013-4152P3MEDIUMCVSS 6.8≤ 3.2.3v3.0.6+10 more2014-01-23
CVE-2013-4152 [MEDIUM] CWE-264 CVE-2013-4152: The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller
The Spring OXM wrapper in Spring Framework before 3.2.4 and 4.0.0.M1, when using the JAXB marshaller, does not disable entity resolution, which allows context-dependent attackers to read arbitrary files, cause a denial of service, and conduct CSRF attacks via an XML external entity declaration in conjunction with an entity reference in a (1) DOMSource
nvd
CVE-2018-15756P3HIGHCVSS 7.5≥ 4.2.0, < 4.3.20≥ 5.0.0, < 5.0.10+1 more2018-10-18
CVE-2018-15756 [HIGH] CVE-2018-15756: Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and o
Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an org.springframework.core.io.Resource. A malicious u
nvd
CVE-2022-22950P3MEDIUMCVSS 6.5fixed in 5.2.20≥ 5.3.0, < 5.3.17+1 more2022-04-01
CVE-2022-22950 [MEDIUM] CWE-770 CVE-2022-22950: n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user
n Spring Framework versions 5.3.0 - 5.3.16 and older unsupported versions, it is possible for a user to provide a specially crafted SpEL expression that may cause a denial of service condition.
nvd
CVE-2018-1272P3HIGHCVSS 7.5≥ 4.3.0, < 4.3.15≥ 5.0, < 5.0.52018-04-06
CVE-2018-1272 [HIGH] CVE-2018-1272: Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported
Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote client, and then uses that input to make a multipart request to another server (server B), it can be expose
nvd
CVE-2018-11040P3HIGHCVSS 7.5fixed in 4.3.18≥ 5.0.0, < 5.0.72018-06-25
CVE-2018-11040 [HIGH] CWE-829 CVE-2018-11040: Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported vers
Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not enabled by default in Spring Framewor
nvd
CVE-2011-2894P3MEDIUMCVSS 6.8≥ 3.0.0, ≤ 3.0.52011-10-04
CVE-2011-2894 [MEDIUM] CWE-502 CVE-2011-2894: Spring Framework 3.0.0 through 3.0.5, Spring Security 3.0.0 through 3.0.5 and 2.0.0 through 2.0.6, a
Spring Framework 3.0.0 through 3.0.5, Spring Security 3.0.0 through 3.0.5 and 2.0.0 through 2.0.6, and possibly other versions deserialize objects from untrusted sources, which allows remote attackers to bypass intended security restrictions and execute untrusted code by (1) serializing a java.lang.Proxy instance and using InvocationHandler, or (2) ac
nvd
CVE-2026-41838P3HIGHCVSS 7.5≥ 5.3.0, < 5.3.49≥ 6.1.0, < 6.1.28+2 more2026-06-09
CVE-2026-41838 [HIGH] CWE-330 CVE-2026-41838: IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, w
IDs for WebSocket sessions in the spring-websocket module are not cryptographically unpredictable, which may be possible to exploit in combination with inadequate authorization rules.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
nvd
CVE-2023-20860P3HIGHCVSS 7.5≥ 5.3.0, < 5.3.26≥ 6.0.0, < 6.0.7+1 more2023-03-27
CVE-2023-20860 [HIGH] CVE-2023-20860: Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring S
Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using "**" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.
nvd
CVE-2015-5211P3CRITICALCVSS 9.6v3.2.0v3.2.1+33 more2017-05-25
CVE-2015-5211 [CRITICAL] CWE-552 CVE-2015-5211: Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and olde
Under some situations, the Spring Framework 4.2.0 to 4.2.1, 4.0.0 to 4.1.7, 3.2.0 to 3.2.14 and older unsupported versions is vulnerable to a Reflected File Download (RFD) attack. The attack involves a malicious user crafting a URL with a batch script extension that results in the response being downloaded rather than rendered and also includes some
nvd
1 / 4Next →