org.springframework:spring-core@4.1.1.RELEASE vulnerabilities
-
latest version
6.1.14
-
latest non vulnerable version
-
first published
19 years ago
-
latest version published
a month ago
-
licenses detected
- [0,)
-
package manager
Direct Vulnerabilities
Known vulnerabilities in the org.springframework:spring-core package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
org.springframework:spring-core is a core package within the spring-framework that contains multiple classes and utilities. Affected versions of this package are vulnerable to Improper Handling of Case Sensitivity due to Note: The fix for CVE-2022-22968 made disallowedFields patterns in DataBinder case insensitive. How to fix Improper Handling of Case Sensitivity? Upgrade |
[,6.1.14)
|
org.springframework:spring-core is a core package within the spring-framework that contains multiple classes and utilities. Affected versions of this package are vulnerable to Improper Input Validation when a user provides malicious input, causing insertion of additional log entries. How to fix Improper Input Validation? Upgrade |
[,5.2.19.RELEASE)
[5.3.0,5.3.14)
|
org.springframework:spring-core is a core package within the spring-framework that contains multiple classes and utilities. Affected versions of this package are vulnerable to Improper Output Neutralization for Logs when a user provides malicious input, causing insertion of additional log entries. How to fix Improper Output Neutralization for Logs? Upgrade |
[5.3.0,5.3.12)
[,5.2.18)
|
Affected versions of the package are vulnerable to Denial Of Service (DoS) via the How to fix Denial of Service (DoS)? Upgrade |
[3.2.8.RELEASE,3.2.14.RELEASE)
[4.1.0.RELEASE,4.1.7.RELEASE)
|