Spring Framework
Vendor:
First CVE: Jan 26, 2014 · Active for 12 years
10
Total CVEs
More Total CVEs than 88% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Spring Framework over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 26, 2014
12 years ago
Most Recent CVE
Jan 10, 2020
2,387 days ago
CVE Severity & Scoring
Spring Framework10 CVEs
70%
30%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local1 (10.0%)
Network4 (40.0%)
Unknown5 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (50.0%)
High0 (0.0%)
Unknown5 (50.0%)
User Interaction
None2 (20.0%)
Unknown5 (50.0%)
Required3 (30.0%)
Privileges Required
Low1 (10.0%)
High0 (0.0%)
None4 (40.0%)
Unknown5 (50.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-6429MEDIUM The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attack | Jan 26, 2014 | 6.8 | 65 | NO | NO |
CVE-2016-5007HIGH Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mappings for authorization and for mapping requests to controllers | May 25, 2017 | 7.5 | 26 | NO | NO |
CVE-2016-9878HIGH An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and | Dec 29, 2016 | 7.5 | 26 | NO | NO |
CVE-2014-0225HIGH When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolutio | May 25, 2017 | 8.8 | 22 | NO | NO |
CVE-2015-3192MEDIUM Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to caus | Jul 12, 2016 | 5.5 | 20 | NO | NO |
CVE-2014-3625MEDIUM Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrar | Nov 20, 2014 | 5.0 | 18 | NO | NO |
CVE-2013-6430MEDIUM The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape certain characters, which allow | Jan 10, 2020 | 5.4 | 17 | NO | NO |
CVE-2014-3578MEDIUM Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL. | Feb 19, 2015 | 5.0 | 17 | NO | NO |
CVE-2015-0201MEDIUM The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspec | Mar 10, 2015 | 5.0 | 15 | NO | NO |
CVE-2014-1904MEDIUM Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers t | Mar 20, 2014 | 4.3 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Spring Framework
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 4.3.0 | 1 | 7.5 | 5.6% | 0 | 0 |
| 4.2.0 | 2 | 7.5 | 4.2% | 0 | 0 |
| 4.1.0 | 3 | 6.0 | 2.4% | 0 | 0 |
| 4.0.0 | 2 | 8.2 | 2.3% | 0 | 0 |
| 3.2.0 | 3 | 7.3 | 2.4% | 0 | 0 |
| 3.1.0 | 1 | 8.8 | 1.7% | 0 | 0 |
| 3.0.0 | 1 | 8.8 | 1.7% | 0 | 0 |