codecentric records
2 published records for vendor codecentric.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-94 Improper Control of Generation of Code ('Code Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
2 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-46166Proof of concept | Spring Boot Admins integrated notifier support allows arbitrary code executioncodecentric · spring boot admin · CWE-94 | Critical9.8 | — | 1.5% | Dec 9, 2022 |
30Monitor | CVE-2023-38286No exploit | Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products, allows sandbox bypasthymeleaf · thymeleaf · CWE-77 | High7.5 | — | 1.0% | Jul 14, 2023 |
- CVE-2022-4616639Monitor
Spring Boot Admins integrated notifier support allows arbitrary code execution
CriticalCVSS 9.8Proof of conceptEPSS 1%codecentric · spring boot adminDec 9, 2022
- CVE-2023-3828630Monitor
Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products, allows sandbox bypas
HighCVSS 7.5No exploitEPSS 1%thymeleaf · thymeleafJul 14, 2023