Spring Data Rest VMware Spring Data Rest

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in VMware Spring Data Rest.

Recent VMware Spring Data Rest Security Advisories

Advisory Title Published
2026-08-20 cve-2026-47849 - HIGH - Spring Data REST allows mutation of identifier and version properties via JSON Patch August 20, 2026
2026-08-20 cve-2026-47850 - MEDIUM - Spring Data REST allows mutation of the version property of immutable aggregates via PUT August 20, 2026
2026-06-09 CVE-2026-41729 - High - CVE-2026-41729: Spring Data REST SpEL Injection via Map Key in JSON Patch June 9, 2026
2026-06-09 CVE-2026-41728 - High - CVE-2026-41728: Spring Data REST JSON Patch bypasses Jackson read-only property protection on nested objects and collections June 9, 2026
2026-06-09 CVE-2026-41730 - Medium - CVE-2026-41730: Spring Data REST exposes persistence-layer internals in error responses June 9, 2026
2026-06-09 CVE-2026-41837 - Medium - CVE-2026-41837: Spring Data REST Querydsl integration exposes Jackson-hidden persistent fields as filter keys June 9, 2026

By the Year

In 2026 there have been 0 vulnerabilities in VMware Spring Data Rest. Spring Data Rest did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 0 0.00
2024 0 0.00
2023 0 0.00
2022 1 3.70
2021 1 5.30

It may take a day or so for new Spring Data Rest vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent VMware Spring Data Rest Security Vulnerabilities

Spring Data REST <=3.7.2 HTTP PATCH Disclosure of hidden entity attributes
CVE-2022-31679 3.7 - Low - September 21, 2022

Applications that allow HTTP PATCH access to resources exposed by Spring Data REST in versions 3.6.0 - 3.5.5, 3.7.0 - 3.7.2, and older unsupported versions, if an attacker knows about the structure of the underlying domain model, they can craft HTTP requests that expose hidden entity attributes.

In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally exposed under URIs
CVE-2021-22047 5.3 - Medium - October 28, 2021

In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally exposed under URIs that can potentially be exposed for unauthorized access depending on the Spring Security configuration.

Exposure of Resource to Wrong Sphere

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for VMware Spring Data Rest or by VMware? Click the Watch button to subscribe.

VMware
Vendor

subscribe