VDB
GHSA-5368-6h4h-gr29
GHSA-5368-6h4h-gr29
PUBLISHED
CVSS 4.699999809265137 MEDIUM
Spring Boot's PID file write follows symlinks at predictable default path
Risk Scores
CVSS 3.1
4.699999809265137
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Maven | org.springframework.boot:spring-boot-cassandra | 4.0.0, 3.5.0, 3.4.0 |
Timeline
- Apr 28, 2026 CVE Published
- May 6, 2026 CVE Updated
- May 7, 2026 Security Advisory