6.2.6
19 years ago
10 days ago
Known vulnerabilities in the org.springframework:spring-core package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
org.springframework:spring-core is a core package within the spring-framework that contains multiple classes and utilities. Affected versions of this package are vulnerable to Improper Handling of Case Sensitivity due to Note: The fix for CVE-2022-22968 made This vulnerability was also fixed in commercial versions 5.3.41 and 6.0.25. How to fix Improper Handling of Case Sensitivity? Upgrade | [,6.1.14) |
org.springframework:spring-core is a core package within the spring-framework that contains multiple classes and utilities. Affected versions of this package are vulnerable to Uncontrolled Resource Consumption ('Resource Exhaustion') via specially crafted HTTP requests. An attacker can cause a denial-of-service condition by sending malicious requests that exploit this issue. Notes: This is only exploitable if the application uses Spring MVC and Spring Security 6.1.6+ or 6.2.1+ is on the classpath. Typically, Spring Boot applications need the How to fix Uncontrolled Resource Consumption ('Resource Exhaustion')? Upgrade | [6.0.15,6.0.16)[6.1.2,6.1.3) |