CVE-2015-5258 Spring Social CSRF

HIGH | NOVEMBER 12, 2015 | CVE-2015-5258
Description Affected Spring Products and Versions Mitigation Credit The issue was first found by Kris Bosch from Include Security. Paul Ambrosini from sourceclear (https://srcclr.com) then identified the root cause, vulnerable library and vulnerable code…

CVE-2015-5211 RFD Attack in Spring Framework

HIGH | OCTOBER 15, 2015 | CVE-2015-5211
Description Affected Spring Products and Versions Mitigation Credit RFD attacks were described by Trustwave in a paper. The issue in the Spring Framework was responsibly reported to Pivotal by Alvaro Muñoz from HPE Security Research. Special thanks to Toshiaki…

CVE-2015-3192 DoS Attack with XML Input

LOW | JUNE 30, 2015 | CVE-2015-3192
Description Affected Spring Products and Versions Mitigation Credit This issue was identified responsibly and reported to Pivotal by Toshiaki Maki of NTT DATA Corporation who also helped to develop and test the solution. References https://jira.spring.io…

CVE-2014-3625 Directory Traversal in Spring Framework

MEDIUM | NOVEMBER 11, 2014 | CVE-2014-3625
Description Affected Spring Products and Versions Mitigation Credit This issue was identified by Toshiaki Maki of NTT DATA Corporation and responsibly reported to Pivotal. References https://jira.spring.io/browse/SPR-12354 https://github.com/spring-projects…

CVE-2014-3578 Directory Traversal in Spring Framework

MEDIUM | SEPTEMBER 05, 2014 | CVE-2014-3578
Description Affected Spring Products and Versions Mitigation Credit This issue was identified by Takeshi Terada of Mitsui Bussan Secure Directions, Inc. and reported to Pivotal via JPCERT/CC. Information that additional versions were affected was discovered by…

CVE-2014-3527 Access Control Bypass in Spring Security

HIGH | AUGUST 15, 2014 | CVE-2014-3527
Description Affected Spring Products and Versions Mitigation Credit This issue was identified by David Ohsie and brought to our attention by the CAS Development team. References http://spring.io/blog/2014/08/15/cve-2014-3527-fixed-in-spring-security-3-2-5-and…

CVE-2014-0097 Blank password may bypass user authentication

HIGH | MARCH 11, 2014 | CVE-2014-0097
Description Affected Spring Products and Versions Mitigation Credit This issue was identified by the Spring Development team. References https://jira.springsource.org/browse/SEC-2500 https://github.com/spring-projects/spring-security/commit/88559882e967085c47a…

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all