CVE-2021-22047
MEDIUMVmware Spring Data Rest < 3.4.13 - Information Disclosure
Title source: ruleDescription
In Spring Data REST versions 3.4.0 - 3.4.13, 3.5.0 - 3.5.5, and older unsupported versions, HTTP resources implemented by custom controllers using a configured base API path and a controller type-level request mapping are additionally exposed under URIs that can potentially be exposed for unauthorized access depending on the Spring Security configuration.
Scores
CVSS v3
5.3
EPSS
0.0032
EPSS Percentile
54.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Classification
CWE
CWE-200
CWE-668
Status
published
Affected Products (2)
vmware/spring_data_rest
< 3.4.13
org.springframework.data/spring-data-rest-core
< 3.4.14Maven
Timeline
Published
Oct 28, 2021
Tracked Since
Feb 18, 2026