Spring Framework
cpe:2.3:a:springsource:spring_framework:*:*:*:*:*:*:*
- >= 7.0.0, <= 7.0.7
- >= 6.2.0, <= 6.2.18
- >= 6.1.0, <= 6.1.27
- >= 5.3.0, <= 5.3.48
A vulnerability allowing information disclosure has been identified in Spring Framework's MVC and WebFlux applications. This issue arises when static resources are resolved, potentially exposing protected resources. The vulnerability affects Spring Framework versions 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, and 5.3.0 through 5.3.48.
Exploitation of this vulnerability could lead to unauthorized access to protected resources, allowing an attacker to retrieve sensitive information that should be restricted.
Users should upgrade to Spring Framework versions 7.0.8, 6.2.19, 6.1.28, or 5.3.49, depending on their current version. Instructions for accessing these versions are available on the Spring Enterprise website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.