All 41 CVE vulnerabilities found in Spring Security, with AI-generated Chinese analysis, references, and POCs.
This page provides a comprehensive aggregation of security weaknesses affecting Spring Security, a critical authentication and authorization framework developed by the Spring team. It collects data on known vulnerabilities, including injection flaws, access control issues, and cryptographic weaknesses, covering reports issued from January 2010 through the present day. By navigating this resource, users can effectively track vendor advisories related to specific releases of the framework, gain a deeper understanding of common weakness classes within the Spring ecosystem, and examine the historical trend of vulnerabilities discovered in this widely used product. The data is compiled from official vendor bulletins, security research publications, and community reports to ensure accuracy and timeliness. This aggregation serves as a central reference point for security professionals, developers, and auditors who need to assess the risk posture of systems relying on Spring Security. Rather than offering marketing materials, the page focuses on technical details, severity ratings, and mitigation strategies associated with each reported flaw. It enables stakeholders to correlate specific versions with known exploits and understand the remediation timeline for critical issues. This structured approach facilitates better decision-making during patch management and vulnerability assessments. Users can filter the list by severity, type, or release version to isolate relevant threats. The goal is to provide clarity in a complex security landscape, helping organizations prioritize fixes based on actual exposure and industry standards. This resource is intended for technical audiences seeking factual, actionable intelligence rather than general awareness.
Vendor: Pivotal
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2022-22978 | VMware Spring Security 授权问题漏洞 CWE-863 | 9.8 | - | 2022-05-19 |
| CVE-2021-22119 | VMware Spring Security 安全漏洞 CWE-400 | 7.5 | - | 2021-06-29 |
| CVE-2021-22112 | Vmware VMware Spring Security 权限许可和访问控制问题漏洞 | 8.8 | - | 2021-02-23 |
| CVE-2020-5408 | Dictionary attack with Spring Security queryable text encryptor CWE-329 | 4.3 | - | 2020-05-14 |
| CVE-2020-5407 | Signature Wrapping Vulnerability with spring-security-saml2-service-provider CWE-347 | 8.1 | - | 2020-05-13 |
| CVE-2019-11272 | PlaintextPasswordEncoder authenticates encoded passwords that are null CWE-287 | 7.7 | - | 2019-06-26 |
| CVE-2019-3795 | Insecure Randomness When Using a SecureRandom Instance Constructed by Spring Security CWE-330 | 6.5 | - | 2019-04-09 |
| CVE-2018-15801 | Authorization Bypass During JWT Issuer Validation with spring-security | 7.4 | - | 2018-12-19 |
| CVE-2014-0097 | Pivotal Spring Security 安全漏洞 | 8.6 | - | 2017-05-25 |
| CVE-2016-5007 | Pivotal Spring Security和Spring Framework 安全漏洞 | 8.2 | - | 2017-05-25 |
| CVE-2014-3527 | Pivotal Spring Security 安全漏洞 | 9.8 | - | 2017-05-25 |
All 41 known CVE vulnerabilities affecting Spring Security with full Chinese analysis, references, and POCs where available.