Applications that allow HTTP PATCH... CVE-2022-31679

- AV AC AU C I A
发布: 2022-09-21
修订: 2024-11-21

Applications that allow HTTP PATCH access to resources exposed by Spring Data REST in versions 3.6.0 - 3.5.5, 3.7.0 - 3.7.2, and older unsupported versions, if an attacker knows about the structure of the underlying domain model, they can craft HTTP requests that expose hidden entity attributes.

0%
暂无可用Exp或PoC
当前有2条受影响产品信息