Where
-Infinity
0

Vendor Risk Score

See how pivotal software compares to other vendors in security performance

View Risk Score →

Software

Severity
4.2
XSS
AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browser) with JavaScript enabled. Using untrusted and compromised Initializr endpoints for the Spring Boot starter wizard can result in arbitrary script execution inside the embedded browser when a developer hovers a dependency checkbox in the New Spring Starter Project wizard. Impact is limited to in-IDE UI spoofing and outbound network beaconing rather than full code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier

First published (updated )
EOL
Jul 31, 2027

End of life: 7/31/2027, Latest version: 4.1.0

First published (updated )
Severity
7

Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusive); upgrade to 5.0.3 or greater.

First published (updated )
Severity
7

In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default web security filter chain; depend on spring-boot-actuator-autoconfigure; not depend on spring-boot-health. If any of the above does not apply, the application is not vulnerable.

Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.

First published (updated )

Latest version: 4.3.5

First published (updated )
EOL
Jul 31, 2027

End of life: 7/31/2027, Latest version: 7.0.8

First published (updated )
EOL
Dec 31, 2026

End of life: 12/31/2026, Latest version: 4.0.7

First published (updated )
EOL
Jul 31, 2026

End of life: 7/31/2026, Latest version: 4.2.9

First published (updated )
EOL
Jun 30, 2026

End of life: 6/30/2026, Latest version: 3.5.16

First published (updated )
EOL
Jan 30, 2026

End of life: 1/30/2026, Latest version: 4.1.8

First published (updated )
EOL
Jun 30, 2026

End of life: 6/30/2026, Latest version: 6.2.19

First published (updated )
EOL
Jun 30, 2026

End of life: 6/30/2026, Latest version: 6.2.19

First published (updated )
EOL
Dec 31, 2025

End of life: 12/31/2025, Latest version: 3.4.13

First published (updated )
EOL
Dec 31, 2025

End of life: 12/31/2025, Latest version: 3.4.13

First published (updated )
EOL
Apr 15, 2025

End of life: 4/15/2025, Latest version: 4.0.9

First published (updated )
EOL
Apr 15, 2025

End of life: 4/15/2025, Latest version: 4.0.9

First published (updated )
EOL
Jun 30, 2025

End of life: 6/30/2025, Latest version: 3.3.13

First published (updated )
EOL
Jun 30, 2025

End of life: 6/30/2025, Latest version: 3.3.13

First published (updated )
EOL
Sep 17, 2024

End of life: 9/17/2024, Latest version: 3.13.7

First published (updated )
EOL
Sep 17, 2024

End of life: 9/17/2024, Latest version: 3.13.7

First published (updated )
EOL
Dec 31, 2024

End of life: 12/31/2024, Latest version: 3.2.12

First published (updated )
EOL
Dec 31, 2024

End of life: 12/31/2024, Latest version: 3.2.12

First published (updated )
EOL
Jun 30, 2025

End of life: 6/30/2025, Latest version: 6.1.21

First published (updated )
EOL
Jun 30, 2025

End of life: 6/30/2025, Latest version: 6.1.21

First published (updated )
EOL
Feb 21, 2024

End of life: 2/21/2024, Latest version: 3.12.14

First published (updated )
EOL
Feb 21, 2024

End of life: 2/21/2024, Latest version: 3.12.14

First published (updated )
EOL
Jun 30, 2024

End of life: 6/30/2024, Latest version: 3.1.12

First published (updated )
EOL
Jun 30, 2024

End of life: 6/30/2024, Latest version: 3.1.12

First published (updated )
EOL
Jun 30, 2024

End of life: 6/30/2024, Latest version: 6.0.23

First published (updated )
EOL
Jun 30, 2024

End of life: 6/30/2024, Latest version: 6.0.23

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203