CVE-2018-1199: Security bypass with static resources

HIGH | JANUARY 29, 2018 | CVE-2018-1199
Description Affected Spring Products and Versions Mitigation Credit The issue was identified by Macchinetta Framework Development Team from NTT Comware, NTT DATA Corporation, and NTT, and responsibly reported to Pivotal. History 2018-01-29: Initial…

CVE-2017-8046: RCE in PATCH requests in Spring Data REST

CRITICAL | SEPTEMBER 21, 2017 | CVE-2017-8046
Description Affected Spring Products and Versions Mitigation Credit This vulnerability was responsibly reported by Man Yue Mo from Semmle and lgtm.com. References https://jira.cupchino.shop/browse/DATAREST-1127 https://jira.cupchino.shop/browse/DATAREST-1152 History…

CVE-2017-8045: Remote code execution in spring-amqp

HIGH | SEPTEMBER 19, 2017 | CVE-2017-8045
Description Affected Spring Products and Versions Mitigation Credit This vulnerability was responsibly reported by Man Yue Mo from Semmle and lgtm.com. References https://jira.cupchino.shop/browse/AMQP-766 https://docs.cupchino.shop/spring-amqp/docs/1.6.11.RELEASE…

CVE-2016-9879 Encoded "/" in path variables

HIGH | DECEMBER 28, 2016 | CVE-2016-9879
Description Affected Spring Products and Versions Mitigation Credit The issue was identified by Shumpei Asahara & Yuji Ito from NTT DATA Corporation and responsibly reported to Pivotal. References http://www.securityfocus.com/archive/1/archive/1/514517/100/…