4.0.5
13 years ago
2 months ago
Known vulnerabilities in the org.springframework.data:spring-data-commons package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
org.springframework.data:spring-data-commons is a maven plugin to centralize common resources and configuration for Spring Data Maven builds. Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the Note: This is only exploitable if the application uses features that forward HTTP-supplied strings to How to fix Allocation of Resources Without Limits or Throttling? Upgrade | [,3.5.12)[4.0.0-M1,4.0.6) |
org.springframework.data:spring-data-commons is a maven plugin to centralize common resources and configuration for Spring Data Maven builds. Affected versions of this package are vulnerable to Denial of Service (DoS) in the parsing of Note: This is only exploitable if the application explicitly exposes an endpoint that accepts How to fix Denial of Service (DoS)? Upgrade | [,3.5.12)[4.0.0-M1,4.0.6) |
org.springframework.data:spring-data-commons is a maven plugin to centralize common resources and configuration for Spring Data Maven builds. Affected versions of this package are vulnerable to Denial of Service (DoS) via the How to fix Denial of Service (DoS)? Upgrade | [,3.5.12)[4.0.0,4.0.6) |
org.springframework.data:spring-data-commons is a maven plugin to centralize common resources and configuration for Spring Data Maven builds. Affected versions of this package are vulnerable to Denial of Service (DoS) via data binding. An attacker can exhaust system memory resources by sending specially crafted HTTP requests. Note: This is only exploitable if both Spring Data Web Support is enabled and a Controller method uses How to fix Denial of Service (DoS)? Upgrade | [,3.5.12)[4.0.0-M1,4.0.6) |