Red hat support for spring boot
This hub aggregates every CVE we track for Red hat support for spring boot, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
10
CVEs tracked
0
Critical
7
High
0
In CISA KEV
Severity distribution
HIGH7MEDIUM3
Monthly trend
1
0
1
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 10 most recently published vulnerabilities affecting Red hat support for spring boot.
- CVE-2023-1932Hibernate-validator: rendering of invalid html with safehtml leads to html injection and xss6.1
- CVE-2023-6841Keycloak: amount of attributes per object is not limited and it may lead to dos7.5
- CVE-2023-5379Undertow: ajp request closes connection exceeding maxrequestsize7.5
- CVE-2023-3223Undertow: outofmemoryerror due to @multipartconfig handling7.5
- CVE-2022-4245Codehaus-plexus: xml external entity (xxe) injection4.3
- CVE-2022-4244Codehaus-plexus: directory traversal7.5
- CVE-2021-46877jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving Jso...7.5
- CVE-2022-25647Deserialization of Untrusted Data7.7
- CVE-2020-36518jackson-databind before 2.13.0 allows a Java StackOverflow exception and denial of service via a large depth of nested objects.7.5
- CVE-2020-10688A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occur...6.1
Product normalization is registry-driven with AI assist and human review. How it works