Spring Framework

Vendor:

First CVE: Jan 26, 2014 · Active for 12 years

10
Total CVEs
More Total CVEs than 88% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Spring Framework over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 26, 2014
12 years ago
Most Recent CVE
Jan 10, 2020
2,387 days ago

CVE Severity & Scoring

Spring Framework10 CVEs
All CVEs352,231 CVEs
MediumHigh
Attack Vector
Local1 (10.0%)
Network4 (40.0%)
Unknown5 (50.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (50.0%)
High0 (0.0%)
Unknown5 (50.0%)
User Interaction
None2 (20.0%)
Unknown5 (50.0%)
Required3 (30.0%)
Privileges Required
Low1 (10.0%)
High0 (0.0%)
None4 (40.0%)
Unknown5 (50.0%)

Top CVEs

Signals from CVEs in this product scope (10 CVEs).

10 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attack
Jan 26, 20146.865NONO
Both Spring Security 3.2.x, 4.0.x, 4.1.0 and the Spring Framework 3.2.x, 4.0.x, 4.1.x, 4.2.x rely on URL pattern mappings for authorization and for mapping requests to controllers
May 25, 20177.526NONO
An issue was discovered in Pivotal Spring Framework before 3.2.18, 4.2.x before 4.2.9, and 4.3.x before 4.3.5. Paths provided to the ResourceServlet were not properly sanitized and
Dec 29, 20167.526NONO
When processing user provided XML documents, the Spring Framework 4.0.0 to 4.0.4, 3.0.0 to 3.2.8, and possibly earlier unsupported versions did not disable by default the resolutio
May 25, 20178.822NONO
Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to caus
Jul 12, 20165.520NONO
Directory traversal vulnerability in Pivotal Spring Framework 3.0.4 through 3.2.x before 3.2.12, 4.0.x before 4.0.8, and 4.1.x before 4.1.2 allows remote attackers to read arbitrar
Nov 20, 20145.018NONO
The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape certain characters, which allow
Jan 10, 20205.417NONO
Directory traversal vulnerability in Pivotal Spring Framework 3.x before 3.2.9 and 4.0 before 4.0.5 allows remote attackers to read arbitrary files via a crafted URL.
Feb 19, 20155.017NONO
The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspec
Mar 10, 20155.015NONO
Cross-site scripting (XSS) vulnerability in web/servlet/tags/form/FormTag.java in Spring MVC in Spring Framework 3.0.0 before 3.2.8 and 4.0.0 before 4.0.2 allows remote attackers t
Mar 20, 20144.315NONO

Exploit Exposure

Signals from CVEs in this product scope (10 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (10 CVEs).

Media Mentions

Signals from CVEs in this product scope (10 CVEs).

Top CNAs Publishing CVEs For Spring Framework

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
4.3.017.55.6%00
4.2.027.54.2%00
4.1.036.02.4%00
4.0.028.22.3%00
3.2.037.32.4%00
3.1.018.81.7%00
3.0.018.81.7%00