org.springframework:spring-web
Maven12 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.springframework:spring-webpage 1 of 1
- CVE-2013-6429NONECVSS 0.0EG 0.0✓ Fixed in 3.2.5.RELEASE2014-01-26
vulnerable: 1.0 ... 3.2.4.RELEASE (67 versions)
The SourceHttpMessageConverter in Spring MVC in Spring Framework before 3.2.5 and 4.0.0.M1 through 4.0.0.RC1 does not disable external entity resolution, which allows remote attackers to read arbitrary files, cause a denial of service, and…
- CVE-2013-6430MEDIUMCVSS 5.4EG 5.4✓ Fixed in 3.2.2.RELEASE2020-01-10
vulnerable: 1.0 ... 3.2.1.RELEASE (64 versions)
The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape certain characters, which allows remote attackers to conduct cross-site scripting (XSS) at…
- CVE-2015-3192MEDIUMCVSS 5.5EG 5.5✓ Fixed in 5.0.0.RC32016-07-12
vulnerable: 5.0.0.RC2
Pivotal Spring Framework before 3.2.14 and 4.x before 4.1.7 do not properly process inline DTD declarations when DTD is not entirely disabled, which allows remote attackers to cause a denial of service (memory consumption and out-of-memory…
- CVE-2016-1000027CRITICALCVSS 9.8EG 9.8✓ Fixed in 6.0.02020-01-02
vulnerable: 1.0 ... 5.3.9 (250 versions)
Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occu…
- CVE-2018-11039MEDIUMCVSS 5.9EG 5.9✓ Fixed in 4.3.182018-06-25
vulnerable: 4.3.0.RELEASE ... 4.3.9.RELEASE (18 versions)
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter…
- CVE-2021-22118HIGHCVSS 7.8EG 7.8✓ Fixed in 5.3.72021-05-27
vulnerable: 5.3.0 ... 5.3.6 (7 versions)
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user c…
- CVE-2024-22243HIGHCVSS 8.1EG 8.12024-02-23
vulnerable: 1.0 ... 5.2.9.RELEASE (210 versions)
Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/…
- CVE-2024-22259HIGHCVSS 8.1EG 8.1✓ Fixed in 5.3.332024-03-16
vulnerable: 1.0 ... 5.3.9 (243 versions)
Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https:/…
- CVE-2024-22262HIGHCVSS 8.1EG 8.1✓ Fixed in 6.1.62024-04-16
vulnerable: 6.1.0 ... 6.1.5 (6 versions)
Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/…
- CVE-2024-38809MEDIUMCVSS 5.3EG 5.3✓ Fixed in 6.1.122024-09-27
vulnerable: 6.1.0 ... 6.1.9 (12 versions)
Applications that parse ETags from "If-Match" or "If-None-Match" request headers are vulnerable to DoS attack. Users of affected versions should upgrade to the corresponding fixed version. Users of older, unsupported versions could enfor…
- CVE-2024-38820LOWCVSS 3.1EG 3.12024-10-18
vulnerable: 1.0 ... 5.3.9 (250 versions)
The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. However, String.toLowerCase() has some Locale dependent exceptions that could potentially result in fields not protected as expected.
- CVE-2025-41234MEDIUMCVSS 6.5EG 6.52025-06-12
vulnerable: 6.0.10 ... 6.0.9 (19 versions)
Description In Spring Framework, versions 6.0.x as of 6.0.5, versions 6.1.x and 6.2.x, an application is vulnerable to a reflected file download (RFD) attack when it sets a “Content-Disposition” header with a non-ASCII charset, where …
Check whether org.springframework:spring-web is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.springframework:spring-web CVEs against the assets you own.
Start Free Scan →