The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Improper Enforcement of Behavioral Workflow vulnerabilities in an interactive lesson.
Start learningUpgrade org.springframework.data:spring-data-rest-core to version 5.0.7, 5.1.1 or higher.
org.springframework.data:spring-data-rest-core is a Spring Data REST.
Affected versions of this package are vulnerable to Improper Enforcement of Behavioral Workflow via the handling of HTTP PUT requests against immutable aggregate types. An attacker can bypass optimistic-locking protections by submitting a crafted request body that includes a manipulated version property, resulting in stale writes being silently accepted and concurrent updates being overwritten.
Note: This is only exploitable if the aggregate root is immutable or allows a body-driven polymorphic subtype change, and the version property is visible to Jackson's deserialization model and not excluded via @JsonIgnore.