Skip to main content
Components
Vulnerabilities
Pricing
MCP
API
Docs
Sign up
Login
Find vulnerabilities. Fix fast with AI.
Search components by package, version, or CVE to get started.
org.springframework/spring-beans 4.1.1.REL… | Sonatype Guide
Get full component data and automated fixes with Sonatype Guide.
Sign up for free
maven
org.springframework
spring-beans
4.1.1.RELEASE
spring-beans 4.1.1.RELEASE
org.springframework
Published
Oct 1, 2014
•
Policy
compliance
maven Registry
Developer Trust Score
Recommended Version:
x.y.z
Recommended upgrade that meets your policy.
Compare Versions
Overview
Overview
Versions
330
Versions
330
Vulnerabilities
2
Vulnerabilities
2
Dependencies
1
Dependencies
1
Severity
Critical
(2)
High
(0)
Medium
(0)
Low
(0)
CVSS Score
0.0
10.0
EPSS Score
0.0
1.0
Malware
KEV Status
Published
Filter
Sort: Published (Newest first)
9.8
CVE-2022-22965
EXPLOITED
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.
affected
Severity
Critical
Published
Apr 1, 2022
9.8
sonatype-2022-1764
Spring-Beans- Remote Code Execution (RCE) [CVE-2022-22965]
affected
Severity
Critical
Published
Mar 30, 2022