GHSA-7phw-cxx7-q9vq
Spring Framework is vulnerable to security bypass via mvcRequestMatcher pattern mismatch
CVEs:GHSA-7phw-cxx7-q9vq
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
Spring Framework is vulnerable to security bypass via mvcRequestMatcher pattern mismatch
CVEs:GHSA-7phw-cxx7-q9vq
Spring Framework is vulnerable to security bypass via mvcRequestMatcher pattern mismatch
CVEs:CVE-2023-20860
Spring Framework vulnerable to denial of service via specially crafted SpEL expression
CVEs:GHSA-564r-hj7v-mcr5
Spring Framework vulnerable to denial of service via specially crafted SpEL expression
CVEs:CVE-2023-20861
CVEs:CVE-2023-20903
GHSA-5rqc-wqwj-478f
CVEs:GHSA-5rqc-wqwj-478f
Spring Vault vulnerable to insertion of sensitive information into a log file
CVEs:CVE-2023-20859
Spring Vault vulnerable to insertion of sensitive information into a log file
CVEs:GHSA-r47r-87p9-8jh3
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.