Applications that allow HTTP PATCH access to resources exposed by Spring Data REST in versions 3.6.0 - 3.5.5, 3.7.0 - 3.7.2, and older unsupported versions, if an attacker knows about the structure of the underlying domain model, they can craft HTTP requests that expose hidden entity attributes.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://tanzu.vmware.com/security/cve-2022-31679 |
|
History
Thu, 22 May 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: vmware
Published: 2022-09-21T17:42:42.000Z
Updated: 2025-05-22T18:32:45.324Z
Reserved: 2022-05-25T00:00:00.000Z
Link: CVE-2022-31679
Updated: 2024-08-03T07:26:00.992Z
Status : Modified
Published: 2022-09-21T18:15:10.093
Modified: 2025-05-22T19:15:31.407
Link: CVE-2022-31679
No data.