Applications that allow HTTP PATCH access to resources exposed by Spring Data REST in versions 3.6.0 - 3.5.5, 3.7.0 - 3.7.2, and older unsupported versions, if an attacker knows about the structure of the underlying domain model, they can craft HTTP requests that expose hidden entity attributes.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://tanzu.vmware.com/security/cve-2022-31679 |
![]() ![]() |
History
Thu, 22 May 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: vmware
Published: 2022-09-21T17:42:42.000Z
Updated: 2025-05-22T18:32:45.324Z
Reserved: 2022-05-25T00:00:00.000Z
Link: CVE-2022-31679

Updated: 2024-08-03T07:26:00.992Z

Status : Modified
Published: 2022-09-21T18:15:10.093
Modified: 2025-05-22T19:15:31.407
Link: CVE-2022-31679

No data.