CVE-2023-34036
Spring HATEOAS vulnerable to Improper Neutralization of HTTP Headers for Scripting Syntax
CVEs:CVE-2023-34036
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
Spring HATEOAS vulnerable to Improper Neutralization of HTTP Headers for Scripting Syntax
CVEs:CVE-2023-34036
Spring HATEOAS vulnerable to Improper Neutralization of HTTP Headers for Scripting Syntax
CVEs:GHSA-7m5c-fgwf-mwph
Access Control Bypass in Spring Security
CVEs:GHSA-3h6f-g5f3-gc4w
Access Control Bypass in Spring Security
CVEs:CVE-2023-34034
Spring Security's authorization rules can be misconfigured when using multiple servlets
CVEs:GHSA-4vpr-xfrp-cj64
Spring Security's authorization rules can be misconfigured when using multiple servlets
CVEs:CVE-2023-34035
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.