CVE-2014-3625 Directory Traversal in Spring Framework

MEDIUM | NOVEMBER 11, 2014 | CVE-2014-3625
Description Affected Spring Products and Versions Mitigation Credit This issue was identified by Toshiaki Maki of NTT DATA Corporation and responsibly reported to Pivotal. References https://jira.spring.io/browse/SPR-12354 https://github.com/spring-projects…

CVE-2014-3578 Directory Traversal in Spring Framework

MEDIUM | SEPTEMBER 05, 2014 | CVE-2014-3578
Description Affected Spring Products and Versions Mitigation Credit This issue was identified by Takeshi Terada of Mitsui Bussan Secure Directions, Inc. and reported to Pivotal via JPCERT/CC. Information that additional versions were affected was discovered by…

CVE-2014-3527 Access Control Bypass in Spring Security

HIGH | AUGUST 15, 2014 | CVE-2014-3527
Description Affected Spring Products and Versions Mitigation Credit This issue was identified by David Ohsie and brought to our attention by the CAS Development team. References http://spring.io/blog/2014/08/15/cve-2014-3527-fixed-in-spring-security-3-2-5-and…

CVE-2014-0097 Blank password may bypass user authentication

HIGH | MARCH 11, 2014 | CVE-2014-0097
Description Affected Spring Products and Versions Mitigation Credit This issue was identified by the Spring Development team. References https://jira.springsource.org/browse/SEC-2500 https://github.com/spring-projects/spring-security/commit/88559882e967085c47a…

CVE-2014-1904 XSS when using Spring MVC

MEDIUM | MARCH 11, 2014 | CVE-2014-1904
Description Affected Spring Products and Versions Mitigation Credit This issue was discovered and reported responsibly to the Pivotal security team by Paul Wowk of CAaNES LLC. References https://jira.springsource.org/browse/SPR-11426 https://github.com/spring…

CVE-2013-6430 Possible XSS when using Spring MVC

LOW | JANUARY 14, 2014 | CVE-2013-6430
Description Affected Spring Products and Versions Mitigation Credit This issue was originally reported to the Spring Framework developers by Jon Passki and the security implications brough to the attention of the Pivotal security team by Arun Neelicattu…

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all