Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Spring by VMware Tanzu — Vulnerabilities & Security Advisories 3

Browse all 3 CVE security advisories affecting Spring by VMware Tanzu. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Spring by VMware Tanzu is a popular Java framework for building enterprise applications with a focus on microservices and cloud-native development. Historically, it has been susceptible to vulnerabilities like remote code execution (RCE), cross-site scripting (XSS), and privilege escalation, often stemming from misconfigurations or insecure default settings. The platform has faced notable security incidents, including CVE-2022-22965 (Spring4Shell) which allowed RCE through specific property injection attacks. While VMware has addressed these issues through patches and security advisories, organizations must remain vigilant about proper configuration and dependency management to mitigate risks associated with this widely used development framework.

Found 1 results / 3 Clear Filters
CVE ID Title CVSS Severity Published
CVE-2024-38827 Spring Security Authorization Bypass for Case Sensitive Comparisons — Spring Security CWE-639 4.8 Medium 2024-12-02

This page lists every published CVE security advisory associated with Spring by VMware Tanzu. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.