Spring MVC and WebFlux applications are vulnerable to Information Disclosure attacks when resolving static resources.
Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.
The code uses a cache that contains sensitive information, but the cache can be read by an actor outside of the intended control sphere.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Spring_framework | Vmware | 5.3.0 (including) | 5.3.49 (excluding) |
| Spring_framework | Vmware | 6.1.0 (including) | 6.1.28 (excluding) |
| Spring_framework | Vmware | 6.2.0 (including) | 6.2.18.1 (excluding) |
| Spring_framework | Vmware | 7.0.0 (including) | 7.0.7.1 (excluding) |
| Libspring-java | Ubuntu | questing | * |