org.springframework.data:spring-data-rest-webmvc

Licenses: Apache-2.0

Direct Vulnerabilities

Known vulnerabilities in the org.springframework.data:spring-data-rest-webmvc package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Improperly Controlled Modification of Dynamically-Determined Object Attributes

[,4.5.12)[5.0.0-M1,5.0.6)
  • H
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')

[,4.5.12)[5.0.0-M1,5.0.6)
  • M
Information Exposure

[,4.5.12)[5.0.0-M1,5.0.6)
  • M
Access Control Bypass

[,4.5.12)[5.0.0-M1,5.0.6)
  • M
Information Exposure

[0,3.6.7)[3.7.0,3.7.3)
  • M
Information Exposure

[3.5.0,3.5.6)[,3.4.14)
  • C
Arbitrary Code Execution

[,2.6.7.RELEASE)

Package versions

276 VERSIONS IN TOTAL See all versions
versionpublisheddirect vulnerabilities
5.1.0-RC117 Apr, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.1.0-M213 Mar, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.1.0-M113 Feb, 2026
  • 0
    C
  • 0
    H
  • 0
    M
  • 0
    L
5.0.517 Apr, 2026
  • 0
    C
  • 2
    H
  • 2
    M
  • 0
    L
5.0.413 Mar, 2026
  • 0
    C
  • 2
    H
  • 2
    M
  • 0
    L
5.0.313 Feb, 2026
  • 0
    C
  • 2
    H
  • 2
    M
  • 0
    L
5.0.216 Jan, 2026
  • 0
    C
  • 2
    H
  • 2
    M
  • 0
    L
5.0.112 Dec, 2025
  • 0
    C
  • 2
    H
  • 2
    M
  • 0
    L
5.0.014 Nov, 2025
  • 0
    C
  • 2
    H
  • 2
    M
  • 0
    L
5.0.0-RC231 Oct, 2025
  • 0
    C
  • 2
    H
  • 2
    M
  • 0
    L