Where
-Infinity
0

Vendor Risk Score

See how pivotal software compares to other vendors in security performance

View Risk Score →

Software

pivotal software bosh cli
33
pivotal software cloud foundry uaa
33
pivotal software cloud foundry elastic runtime
18
pivotal software spring framework
9
pivotal software cloud foundry
8
pivotal software concourse
7
pivotal software spring boot
6
pivotal software rabbitmq
5
pivotal software spring security
5
pivotal software cloud foundry ops manager
4
pivotal software spring data rest
4
pivotal software cloud foundry cf
3
pivotal software gemfire for pivotal cloud foundry
3
pivotal software spring data commons
3
pivotal software cloud foundry uaa-release
2
pivotal software credhub-release
2
pivotal software login-server
2
pivotal software operations manager
2
pivotal software pivotal container service
2
pivotal software spring batch
2
pivotal software windows stemcells
2
pivotal software bits service
1
pivotal software broker api
1
pivotal software cf-deployment
1
pivotal software cloud foundry cf-deployment
1
pivotal software cloud foundry diego
1
pivotal software cloud foundry smb volume
1
pivotal software greenplum command center
1
pivotal software grootfs
1
pivotal software on demand services sdk
1
pivotal software spring authorization server
1
pivotal software spring batch admin
1
pivotal software spring cloud config
1
pivotal software spring cloud config server
1
pivotal software spring cloud stream avro
1
pivotal software spring data java persistance api
1
pivotal software spring data java persistence api
1
pivotal software spring for graphql
1
pivotal software spring ldap
1
pivotal software spring security oauth
1
pivotal software spring tools for eclipse
1
pivotal software spring web services
1
Severity
8.2
XSS
AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. When using the DefaultConsentPage, an attacker can craft an OAuth2 authorization request containing a malicious value that is stored server-side and later rendered unencoded in the default consent page presented to the end user. Spring Authorization Server 1.5.0 - 1.5.8 Spring Authorization Server 1.4.0 - 1.4.11

First published (updated )
Severity
3.8
AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N

Improper caching of the original content type in Spring Cloud Stream Avro. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6

First published (updated )
Severity
8.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

The GraphiQL page bundled with Spring for GraphQL loads JavaScript libraries from a public CDN, without Subresource Integrity checks. An attacker can inject malicious code in those scripts and execute arbitrary code on the browser loading the GraphiQL page. Spring for GraphQL 2.0.0 - 2.0.4 Spring for GraphQL 1.4.0 - 1.4.6 Spring for GraphQL 1.1.0 - 1.3.9 Spring for GraphQL 1.0.0 - 1.0.7

First published (updated )
Severity
9.8
CRLF Injection
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fragments. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19

First published (updated )
Severity
7.5
Path Traversal
AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier

First published (updated )
Severity
4.2
XSS
AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

Spring Tools for Eclipse renders Spring Boot starter wizard dependency tooltips in a native embedded browser (SWT Browser) with JavaScript enabled. Using untrusted and compromised Initializr endpoints for the Spring Boot starter wizard can result in arbitrary script execution inside the embedded browser when a developer hovers a dependency checkbox in the New Spring Starter Project wizard. Impact is limited to in-IDE UI spoofing and outbound network beaconing rather than full code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier

First published (updated )
EOL
Jul 31, 2027

End of life: 7/31/2027, Latest version: 4.1.1

First published (updated )
Severity
7

Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusive); upgrade to 5.0.3 or greater.

First published (updated )
Severity
7

In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default web security filter chain; depend on spring-boot-actuator-autoconfigure; not depend on spring-boot-health. If any of the above does not apply, the application is not vulnerable.

Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.

First published (updated )

Latest version: 4.3.5

First published (updated )
EOL
Jul 31, 2027

End of life: 7/31/2027, Latest version: 7.0.9

First published (updated )
EOL
Dec 31, 2026

End of life: 12/31/2026, Latest version: 4.0.8

First published (updated )
EOL
Jul 31, 2026

End of life: 7/31/2026, Latest version: 4.2.9

First published (updated )
EOL
Jun 30, 2026

End of life: 6/30/2026, Latest version: 3.5.16

First published (updated )
EOL
Jan 30, 2026

End of life: 1/30/2026, Latest version: 4.1.8

First published (updated )
EOL
Jun 30, 2026

End of life: 6/30/2026, Latest version: 6.2.19

First published (updated )
EOL
Jun 30, 2026

End of life: 6/30/2026, Latest version: 6.2.19

First published (updated )
EOL
Dec 31, 2025

End of life: 12/31/2025, Latest version: 3.4.13

First published (updated )
EOL
Dec 31, 2025

End of life: 12/31/2025, Latest version: 3.4.13

First published (updated )
EOL
Apr 15, 2025

End of life: 4/15/2025, Latest version: 4.0.9

First published (updated )
EOL
Apr 15, 2025

End of life: 4/15/2025, Latest version: 4.0.9

First published (updated )
EOL
Jun 30, 2025

End of life: 6/30/2025, Latest version: 3.3.13

First published (updated )
EOL
Jun 30, 2025

End of life: 6/30/2025, Latest version: 3.3.13

First published (updated )
EOL
Sep 17, 2024

End of life: 9/17/2024, Latest version: 3.13.7

First published (updated )
EOL
Sep 17, 2024

End of life: 9/17/2024, Latest version: 3.13.7

First published (updated )
EOL
Dec 31, 2024

End of life: 12/31/2024, Latest version: 3.2.12

First published (updated )
EOL
Dec 31, 2024

End of life: 12/31/2024, Latest version: 3.2.12

First published (updated )
EOL
Jun 30, 2025

End of life: 6/30/2025, Latest version: 6.1.21

First published (updated )
EOL
Jun 30, 2025

End of life: 6/30/2025, Latest version: 6.1.21

First published (updated )
EOL
Feb 21, 2024

End of life: 2/21/2024, Latest version: 3.12.14

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203