VMware Spring Data Rest
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in VMware Spring Data Rest.
Recent VMware Spring Data Rest Security Advisories
| Advisory | Title | Published |
|---|---|---|
| 2026-08-20 | cve-2026-47849 - HIGH - Spring Data REST allows mutation of identifier and version properties via JSON Patch | August 20, 2026 |
| 2026-08-20 | cve-2026-47850 - MEDIUM - Spring Data REST allows mutation of the version property of immutable aggregates via PUT | August 20, 2026 |
| 2026-06-09 | CVE-2026-41729 - High - CVE-2026-41729: Spring Data REST SpEL Injection via Map Key in JSON Patch | June 9, 2026 |
| 2026-06-09 | CVE-2026-41728 - High - CVE-2026-41728: Spring Data REST JSON Patch bypasses Jackson read-only property protection on nested objects and collections | June 9, 2026 |
| 2026-06-09 | CVE-2026-41730 - Medium - CVE-2026-41730: Spring Data REST exposes persistence-layer internals in error responses | June 9, 2026 |
| 2026-06-09 | CVE-2026-41837 - Medium - CVE-2026-41837: Spring Data REST Querydsl integration exposes Jackson-hidden persistent fields as filter keys | June 9, 2026 |
By the Year
In 2026 there have been 0 vulnerabilities in VMware Spring Data Rest. Spring Data Rest did not have any published security vulnerabilities last year.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 0 | 0.00 |
| 2025 | 0 | 0.00 |
| 2024 | 0 | 0.00 |
| 2023 | 0 | 0.00 |
| 2022 | 1 | 3.70 |
| 2021 | 1 | 5.30 |
It may take a day or so for new Spring Data Rest vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent VMware Spring Data Rest Security Vulnerabilities
Spring Data REST <=3.7.2 HTTP PATCH Disclosure of hidden entity attributes
CVE-2022-31679
3.7 - Low
- September 21, 2022
Applications that allow HTTP PATCH access to resources exposed by Spring Data REST in versions 3.6.0 - 3.5.5, 3.7.0 - 3.7.2, and older unsupported versions, if an attacker knows about the structure of the underlying domain model, they can craft HTTP requests that expose hidden entity attributes.
In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally exposed under URIs
CVE-2021-22047
5.3 - Medium
- October 28, 2021
In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally exposed under URIs that can potentially be exposed for unauthorized access depending on the Spring Security configuration.
Exposure of Resource to Wrong Sphere
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for VMware Spring Data Rest or by VMware? Click the Watch button to subscribe.