Spring Framework
cpe:2.3:a:springsource:spring_framework:*:*:*:*:*:*:*
- >= 7.0.0, <= 7.0.7
- >= 6.2.0, <= 6.2.18
- >= 6.1.0, <= 6.1.27
- >= 5.3.0, <= 5.3.48
A vulnerability exists in Spring Framework's Expression Language (SpEL) evaluation logic, allowing arbitrary zero-argument method invocations. This issue arises even in restricted or read-only contexts, potentially enabling attackers to execute unintended application logic. The vulnerability affects Spring Framework versions 7.0.0 through 7.0.7, 6.2.0 through 6.2.18, 6.1.0 through 6.1.27, and 5.3.0 through 5.3.48.
Exploitation of this vulnerability could lead to unauthorized method executions, allowing attackers to manipulate application behavior or access sensitive information.
Users should upgrade to Spring Framework versions 7.0.8, 6.2.19, 6.1.28, or 5.3.49. Instructions for upgrading to these versions are available on the Spring Release Calendar.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.