imPC@ndo IT

Tracker / CVE-2022-31679

CVE-2022-31679

Low 3.7

Applications that allow HTTP PATCH access to resources exposed by Spring Data REST in versions 3.6.0 - 3.5.5, 3.7.0 - 3.7.2, and older unsupported versions, if an attacker knows about the structure of the underlying domain model, they can craft HTTP requests that expose hidden entity attributes.

Affected products and versions

vmware spring_data_rest · 3.6.0 → 3.6.7
vmware spring_data_rest · 3.7.0 → 3.7.3

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References