Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37252
HistorySep 23, 2022 - 9:23 a.m.

Information Disclosure

2022-09-2309:23:35
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
20
vulnerability
information disclosure
spring-data-rest-webmvc
json patch
entity attributes
http requests

EPSS

0.001

Percentile

42.1%

spring-data-rest-webmvc is vulnerable to information disclosure. The vulnerability exists due to the improper implementation of the JSON patch in the library, allowing an attacker to get information about the hidden entity attributes through maliciously crafted HTTP requests.

EPSS

0.001

Percentile

42.1%