VMSA-2024-0003
VMSA-2024-0003: Questions & Answers
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
VMSA-2024-0003: Questions & Answers
Spring Security's spring-security.xsd file is world writable
CVEs:GHSA-9gp8-6cg8-7h34
Spring Web vulnerable to Open Redirect or Server Side Request Forgery
CVEs:GHSA-ccgv-vj62-xf9h
Spring Web vulnerable to Open Redirect or Server Side Request Forgery
CVEs:CVE-2024-22243
Broken Access Control in Spring Security With Direct Use of isFullyAuthenticated
CVEs:GHSA-w3w6-26f2-p474
Broken Access Control in Spring Security With Direct Use of isFullyAuthenticated
CVEs:CVE-2024-22234
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.