Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.6
CVE-2015-5211: Spring Core library may let attackers run code
CVE-2015-5211 · published 2 days ago
Summary
The Spring Core component used in Java applications had a weakness that could allow an attacker to execute code on the server. This could lead to unauthorized access or data loss. Apply the latest released updates for Spring Core to fix the issue.
What to do
- Update springframework org.springframework:spring-core to version 4.1.8.
- Update springframework org.springframework:spring-core to version 4.2.2.
- Update springframework org.springframework:spring-core to version 3.2.15.
- Update org.springframework:spring-core to version 4.0.3.RELEASE-aikido.1.
- Update io.root.org.springframework:spring-core to version 4.0.3.RELEASE-root.io.1.
- Update org.springframework:spring-core to version 4.0.3.RELEASE-aikido.2.
- Update io.root.org.springframework:spring-core to version 4.0.3.RELEASE-root.io.2.
- Update org.springframework:spring-core to version 4.0.3.RELEASE-aikido.3.
- Update io.root.org.springframework:spring-core to version 4.0.3.RELEASE-root.io.3.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| maven | springframework | org.springframework:spring-core |
>= 4.0.0, < 4.1.8 >= 4.2.0, < 4.2.2 < 3.2.15 Fix: upgrade to 4.1.8
|
| – | vmware | spring_framework |
3.2.0 3.2.1 3.2.2 3.2.3 3.2.4 3.2.5 3.2.6 3.2.7 3.2.8 3.2.9 3.2.10 3.2.11 23 more version ranges
cpe:2.3:a:vmware:spring_framework:3.2.0:*:*:*:*:*:*:* |
| – | debian | debian_linux |
8.0 cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
| Root:Maven | – | org.springframework:spring-core |
< 4.0.3.RELEASE-aikido.1 < 4.0.3.RELEASE-aikido.2 < 4.0.3.RELEASE-aikido.3 Fix: upgrade to 4.0.3.RELEASE-aikido.1
|
| Root:Maven | – | io.root.org.springframework:spring-core |
< 4.0.3.RELEASE-root.io.1 < 4.0.3.RELEASE-root.io.2 < 4.0.3.RELEASE-root.io.3 Fix: upgrade to 4.0.3.RELEASE-root.io.1
|
Original advisory text
CVE-2015-5211 in org.springframework:spring-core - Patched by Root
Root has patched CVE-2015-5211 in the org.springframework:spring-core package for Root:Maven. Multiple fixed versions available.
References
- https://nvd.nist.gov/vuln/detail/CVE-2015-5211
- https://github.com/advisories/GHSA-pgf9-h69p-pcgf
- https://lists.debian.org/debian-lts-announce/2019/07/msg00012.html
- https://pivotal.io/security/cve-2015-5211
- https://github.com/spring-projects/spring-framework/commit/03f547eb9868f48f44d59...
- https://github.com/spring-projects/spring-framework/commit/2bd1daa75ee0b8ec33608...
- https://github.com/spring-projects/spring-framework/commit/a95c3d820dbc4c3ae752f...
- https://www.trustwave.com/Resources/SpiderLabs-Blog/Reflected-File-Download---A-...
- https://www.trustwave.com/Resources/SpiderLabs-Blog/Reflected-File-Download---A-... Exploit Technical Description
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit (estimated)
- Gives an attacker full control (estimated)
Severity
9.6
Critical
Type
CWE-20Improper Input Validation
CWE-552Files or Directories Accessible to External Parties
Timeline
Published9 Oct 2026
Updated9 Oct 2026
First seen6 Mar 2026
Track software like this
Free during beta