Known vulnerabilities in Spring for Apache Kafka
Vendor:
Spring
Software:
Spring for Apache Kafka
Software CPE:
cpe:2.3:a:spring:spring_for_apache_kafka:*:*:*:*:*:*:*:*
Website:
https://spring.io/
Total vulnerabilities:
2
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.2
Breakdown by Severity Chart
4.1.0
4.0.6
3.3.16
4.0.5
3.3.15
4.0.4
3.3.14
4.0.3
3.3.13
4.0.2
3.3.12
4.0.1
4.0.0
3.3.11
3.3.10
3.3.9
3.3.8
3.3.7
3.2.10
3.3.6
3.2.9
3.3.5
3.3.4
3.2.8
3.3.3
3.2.7
3.3.2
3.3.1
3.2.6
3.3.0
3.2.5
3.1.10
3.2.4
3.1.9
3.2.3
3.1.8
3.2.2
3.1.7
3.2.1
3.1.6
3.2.0
3.1.5
3.0.17
3.1.4
3.0.16
3.1.3
3.0.15
3.1.2
3.0.14
3.1.1
3.1.0
3.0.13
3.0.12
2.9.13
3.0.11
2.9.12
3.0.10
3.0.9
3.0.8
3.0.7
3.0.6
3.0.5
3.0.4
3.0.3
3.0.2
3.0.1
3.0.0
2.9.11
2.9.10
2.9.9
2.9.8
2.9.7
2.9.6
2.9.5
2.9.4
2.9.3
2.9.2
2.9.1
2.9.0
2.8.11
2.8.10
2.8.9
2.8.8
2.8.7
2.8.6
2.8.5
2.8.4
2.8.3
2.8.2
2.8.1
2.8.0
2.7.14
2.7.13
2.7.12
2.7.11
2.7.10
2.7.9
2.7.8
2.7.7
2.7.6
2.7.5
2.7.4
2.7.3
2.7.2
2.7.1
2.7.0
2.6.13
2.6.12
2.6.11
2.6.10
2.6.9
2.6.8
2.6.7
2.6.6
2.6.5
2.6.4
2.6.3
2.6.2
2.6.1
2.6.0
Vulnerabilities (2)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU83312 - Authorization Bypass Through User-Controlled Key CVE-2023-44981 |
CWE-639 | Medium | 3.0.13, 3.1.0 | 20.11.2023 |
SB2023112072 SB2023112073 SB2023112077 and 45 more |
||
| #VU79928 - Deserialization of Untrusted Data CVE-2023-34040 |
CWE-502 | Medium | 2.9.11, 3.0.10 | 23.08.2023 |
SB2023082369 SB2023110816 SB2023121130 and 3 more |