CVE-2018-1275: Address partial fix for CVE-2018-1270

CRITICAL | APRIL 09, 2018 | CVE-2018-1275
Description Affected Spring Products and Versions Mitigation Credit This original issue CVE-2018-1270 was identified and responsibly reported by Alvaro Muñoz (@pwntester), Micro Focus Fortify. The subsequent CVE-2018-1275 partial fix was identified and…

CVE-2018-1229: Stored XSS in file upload of Spring Batch Admin

LOW | MARCH 16, 2018 | CVE-2018-1229
Description Affected Spring Products and Versions Mitigation Credit This vulnerability was responsibly reported by Wen Bin Kong. References https://docs.spring.io/spring-batch-admin https://github.com/spring-projects/spring-batch-admin/blob/master/MIGRATION.md…

CVE-2018-1199: Security bypass with static resources

HIGH | JANUARY 29, 2018 | CVE-2018-1199
Description Affected Spring Products and Versions Mitigation Credit The issue was identified by Macchinetta Framework Development Team from NTT Comware, NTT DATA Corporation, and NTT, and responsibly reported to Pivotal. History 2018-01-29: Initial…

CVE-2017-8046: RCE in PATCH requests in Spring Data REST

CRITICAL | SEPTEMBER 21, 2017 | CVE-2017-8046
Description Affected Spring Products and Versions Mitigation Credit This vulnerability was responsibly reported by Man Yue Mo from Semmle and lgtm.com. References https://jira.spring.io/browse/DATAREST-1127 https://jira.spring.io/browse/DATAREST-1152 History…

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all