- How many CVEs does spring-cloud have?
- spring-cloud has 26 published CVE records since 2019, including 10 in the last two years.
- How many spring-cloud CVEs are in CISA KEV?
- Yes — 3 of spring-cloud's CVEs are listed in CISA's Known Exploited Vulnerabilities catalog, confirmed exploited in the wild and carrying a CISA remediation deadline.
- Which spring-cloud products have the most CVEs?
- The spring-cloud products with the most published CVEs are spring-cloud-config, org.springframework.cloud:spring-cloud-config-server, spring-cloud-gateway, spring-cloud-function, org.springframework.cloud:spring-cloud-function-context.
- What are the most common weakness types in spring-cloud CVEs?
- spring-cloud's CVEs most often map to these CWE weakness types: CWE-94 (Improper Control of Generation of Code ('Code Injection')), CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')), CWE-23 (Relative Path Traversal), CWE-89 (Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')).
- Are there public exploits for spring-cloud vulnerabilities?
- Yes — 6 of spring-cloud's CVEs have a known public exploit.
- How many critical spring-cloud vulnerabilities are there?
- spring-cloud has 4 critical and 11 high-severity CVEs.
- What is the average severity of spring-cloud CVEs?
- The average CVSS base score across spring-cloud's scored CVEs is 7.4.