cbcvebase.

Vmware Spring Security vulnerabilities

36 known vulnerabilities affecting vmware/spring_security.

Total CVEs
36
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL5HIGH16MEDIUM14LOW1

Vulnerabilities

Page 2 of 2
CVE-2016-9879P3HIGHCVSS 7.5v3.2.0v3.2.1+13 more2017-01-06
CVE-2016-9879 [HIGH] CWE-417 CVE-2016-9879: An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x befo An issue was discovered in Pivotal Spring Security before 3.2.10, 4.1.x before 4.1.4, and 4.2.x before 4.2.1. Spring Security does not consider URL path parameters when processing security constraints. By adding a URL path parameter with an encoded "/" to a request, an attacker may be able to bypass a security constraint. The root cause of this issue is
nvd
CVE-2014-0097P3HIGHCVSS 7.3v3.1.0v3.1.1+6 more2017-05-25
CVE-2014-0097 [HIGH] CWE-287 CVE-2014-0097: The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not c The ActiveDirectoryLdapAuthenticator in Spring Security 3.2.0 to 3.2.1 and 3.1.0 to 3.1.5 does not check the password length. If the directory allows anonymous binds then it may incorrectly authenticate a user who supplies an empty password.
nvd
CVE-2020-5408P3MEDIUMCVSS 6.5≥ 4.2.0, < 4.2.16≥ 5.0.0, < 5.0.16+1 more2020-05-14
CVE-2020-5408 [MEDIUM] CWE-329 CVE-2020-5408: Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x pr Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of the queryable text encryptor. A malicious user with access to the data that has been encrypted using such an encryptor may be able to d
nvd
CVE-2023-20862P3MEDIUMCVSS 6.3≥ 5.7.0, < 5.7.8≥ 5.8.0, < 5.8.3+2 more2023-04-19
CVE-2023-20862 [MEDIUM] CWE-459 CVE-2023-20862: In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean the security context if using serialized versions. Additionally, it is not possible to explicitly save an empty security context to the HttpSessionSecurityContextRepository. This vulnerabilit
nvd
CVE-2026-22748P3MEDIUMCVSS 6.5fixed in 6.3.15≥ 6.4.0, < 6.4.15+2 more2026-04-22
CVE-2026-22748 [MEDIUM] CWE-20 CVE-2026-22748: Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtD Vulnerability in Spring Spring Security. When an application configures JWT decoding with NimbusJwtDecoder or NimbusReactiveJwtDecoder, it must configure an OAuth2TokenValidator separately, for example by calling setJwtValidator.This issue affects Spring Security: from 6.3.0 through 6.3.14, from 6.4.0 through 6.4.14, from 6.5.0 through 6.5.9, from 7.
nvd
CVE-2026-41706P4MEDIUMCVSS 6.1fixed in 5.7.24≥ 5.8.0, < 5.8.26+4 more2026-06-10
CVE-2026-41706 [MEDIUM] CWE-601 CVE-2026-41706: Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication reque Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser cookie so that users can be redirected back to their intended destination after a successful login. In affected versions, the full absolute URL is stored in the cookie and is used without validation as the post-login redirect targe
nvd
CVE-2026-41008P4MEDIUMCVSS 6.1≥ 7.0.0, < 7.0.5.12026-06-10
CVE-2026-41008 [MEDIUM] CWE-601 CVE-2026-41008: Spring Security Authorization Server's authorization endpoint performs insufficient validation of th Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a malicious authorization request containing an invalid request_uri and an arbitrary, unvalidated redirect_uri, which can lead to an Open Redirect vulnerability. Affected versions: Spring Security 7.0.0
nvd
CVE-2026-41003P4MEDIUMCVSS 5.4≥ 5.7.0, < 5.7.24≥ 5.8.0, < 5.8.26+4 more2026-06-10
CVE-2026-41003 [MEDIUM] CWE-79 CVE-2026-41003: An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code o An attacker able to influence values in RelyingPartyRegistration may be able to run arbitrary code on HTML forms generated by Spring Security filters. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.
nvd
CVE-2018-1199P4MEDIUMCVSS 5.3≥ 4.1.0, < 4.1.5≥ 4.2.0, < 4.2.4+1 more2018-03-16
CVE-2018-1199 [MEDIUM] CWE-20 CVE-2018-1199: Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Security (Spring Security 4.1.x before 4.1.5, 4.2.x before 4.2.4, and 5.0.x before 5.0.1; and Spring Framework 4.3.x before 4.3.14 and 5.0.x before 5.0.3) does not consider URL path parameters when processing security constraints. By adding a URL path parameter with special encodings, an attacker may be able to bypass a security constraint. The
nvd
CVE-2026-41694P4MEDIUMCVSS 5.3≥ 5.7.0, < 5.7.24≥ 5.8.0, < 5.8.26+4 more2026-06-10
CVE-2026-41694 [MEDIUM] CWE-347 CVE-2026-41694: Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and Lo Since Spring Security SAML decrypts SAML Responses as well as elements of SAML LogoutRequests and LogoutResponses without requiring a valid signature, attackers may be able to craft these SAML payloads and use the Service Provider as a decryption oracle. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.
nvd
CVE-2022-22976P4MEDIUMCVSS 5.3≥ 5.2.1, < 5.5.7≥ 5.6.0, < 5.6.4+2 more2022-05-19
CVE-2022-22976 [MEDIUM] CWE-190 CVE-2022-22976: Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported version Spring Security versions 5.5.x prior to 5.5.7, 5.6.x prior to 5.6.4, and earlier unsupported versions contain an integer overflow vulnerability. When using the BCrypt class with the maximum work factor (31), the encoder does not perform any salt rounds, due to an integer overflow error. The default settings are not affected by this CVE.
nvd
CVE-2019-3795P4MEDIUMCVSS 5.3≥ 4.2.0, < 4.2.12≥ 5.0.0, < 5.0.12+1 more2019-04-09
CVE-2019-3795 [MEDIUM] CWE-330 CVE-2019-3795: Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 cont Spring Security versions 4.2.x prior to 4.2.12, 5.0.x prior to 5.0.12, and 5.1.x prior to 5.1.5 contain an insecure randomness vulnerability when using SecureRandomFactoryBean#setSeed to configure a SecureRandom instance. In order to be impacted, an honest application must provide a seed and make the resulting random material available to an attacker
nvd
CVE-2023-34035P4MEDIUMCVSS 5.3≥ 5.8.0, < 5.8.5≥ 6.0.0, < 6.0.5+2 more2023-07-18
CVE-2023-34035 [MEDIUM] CWE-863 CVE-2023-34035: Spring Security versions 5.8 prior to 5.8.5, 6.0 prior to 6.0.5, and 6.1 prior to 6.1.2 could be sus Spring Security versions 5.8 prior to 5.8.5, 6.0 prior to 6.0.5, and 6.1 prior to 6.1.2 could be susceptible to authorization rule misconfiguration if the application uses requestMatchers(String) and multiple servlets, one of them being Spring MVC’s DispatcherServlet. (DispatcherServlet is a Spring MVC component that maps HTTP endpoints to methods o
nvd
CVE-2023-34042P4MEDIUMCVSS 5.5≥ 5.8.4, < 5.8.7≥ 6.0.4, < 6.0.7+4 more2024-02-05
CVE-2023-34042 [MEDIUM] CWE-732 CVE-2023-34042: The spring-security.xsd file inside the spring-security-config jar is world writable which means th The spring-security.xsd file inside the spring-security-config jar is world writable which means that if it were extracted it could be written by anyone with access to the file system. While there are no known exploits, this is an example of “CWE-732: Incorrect Permission Assignment for Critical Resource” and could result in an exploit. Users shoul
nvd
CVE-2026-22751P4MEDIUMCVSS 4.8≥ 6.4.0, < 6.4.16≥ 6.5.0, < 6.5.10+1 more2026-04-21
CVE-2026-22751 [MEDIUM] CWE-367 CVE-2026-22751: Vulnerability in Spring Spring Security. Applications that explicitly configure One-Time Token login Vulnerability in Spring Spring Security. Applications that explicitly configure One-Time Token login with JdbcOneTimeTokenService are vulnerable to a Time-of-check Time-of-use (TOCTOU) race condition. This issue affects Spring Security: from 6.4.0 through 6.4.15, from 6.5.0 through 6.5.9, from 7.0.0 through 7.0.4.
nvd
CVE-2026-22746P4LOWCVSS 3.7fixed in 5.7.23≥ 5.8.0, < 5.8.25+4 more2026-04-22
CVE-2026-22746 [LOW] CWE-208 CVE-2026-22746: Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAc Vulnerability in Spring Spring Security. If an application is using the UserDetails#isEnabled, #isAccountNonExpired, or #isAccountNonLocked user attributes, to enable, expire, or lock users, then DaoAuthenticationProvider's timing attack defense can be bypassed for users who are disabled, expired, or locked.This issue affects Spring Security: from 5.7.
nvd
Vmware Spring Security vulnerabilities | cvebase