Spring Framework是美国Spring团队的一套开源的Java、JavaEE应用程序框架。该框架可帮助开发人员构建高质量的应用。 Spring Framework存在输入验证错误漏洞。攻击者利用该漏洞通过 WebSocket 上的 STOMP 导致 Spring Framework 的致命错误,以触发拒绝服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | Spring Framework | Spring Framework versions 5.3.x prior to 5.3.20, 5.2.x prior to 5.2.22 and all old and unsupported v |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | Spring Framework | Spring Framework versions 5.3.x prior to 5.3.20, 5.2.x prior to 5.2.22 and all old and unsupported versions | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/tchize/CVE-2022-22971 | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-29999 | Insurance Management System SQL注入漏洞 | |
| CVE-2022-29745 | Money Transfer Management System SQL注入漏洞 | |
| CVE-2022-29307 | Ionize 代码注入漏洞 | |
| CVE-2022-28919 | DokuWiki 跨站脚本漏洞 | |
| CVE-2022-28920 | Tieba-Cloud-Sign 跨站脚本漏洞 | |
| CVE-2021-33130 | Intel RealSense ID Solution F450 安全漏洞 | |
| CVE-2022-21131 | Intel Xeon Processors 安全漏洞 | |
| CVE-2022-21136 | Intel Xeon Processors 输入验证错误漏洞 | |
| CVE-2022-29738 | Money Transfer Management System SQL注入漏洞 | |
| CVE-2022-29998 | Insurance Management System SQL注入漏洞 | |
| CVE-2022-29746 | Money Transfer Management System SQL注入漏洞 | |
| CVE-2022-29303 | Contec SolarView Compact 操作系统命令注入漏洞 | |
| CVE-2022-29302 | Contec SolarView Compact 安全漏洞 | |
| CVE-2022-29298 | Contec SolarView Compact 路径遍历漏洞 | |
| CVE-2022-30000 | Insurance Management System SQL注入漏洞 | |
| CVE-2022-30001 | Insurance Management System SQL注入漏洞 | |
| CVE-2022-30002 | Insurance Management System SQL注入漏洞 | |
| CVE-2022-29985 | Online Sports Complex Booking System SQL注入漏洞 | |
| CVE-2022-29986 | Online Sports Complex Booking System SQL注入漏洞 | |
| CVE-2022-29987 | Online Sports Complex Booking System SQL注入漏洞 |
Showing top 20 of 94 CVEs. View all on vendor page → →
No comments yet