[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2011-2730":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T02:55:30.529Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":18,"aliases":19,"duplicate_of":9,"upstream":21,"downstream":22,"duplicates":37,"related":38,"reserved_at":9,"published_at":39,"modified_at":40,"state":41,"summary":42,"references_raw":50,"kevs":161,"epss":162,"epss_history":165,"metrics":389,"affected":394},"CVE-2011-2730","VMware SpringSource Spring Framework before 2.5.6.SEC03, 2.5.7.SR023, and 3.x before 3.0.6, when a container supports Expression Language (EL), evaluates EL expressions in tags twice, which allows remote attackers to obtain sensitive information via a (1) name attribute in a (a) spring:hasBindErrors tag; (2) path attribute in a (b) spring:bind or (c) spring:nestedpath tag; (3) arguments, (4) code, (5) text, (6) var, (7) scope, or (8) message attribute in a (d) spring:message or (e) spring:theme tag; or (9) var, (10) scope, or (11) value attribute in a (f) spring:transform tag, aka \"Expression Language Injection.\"",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":9,"likelihood_of_exploit":9,"capec":17},"CWE-16","Configuration","Weaknesses in this category are typically introduced during the configuration of the software.","category","Obsolete",[],[],[20],"GHSA-wv88-pf73-x22p",[],[23,25,27,29,31,33,35],{"_key":24},"DSA-2504-1",{"_key":26},"RHSA-2013:0191",{"_key":28},"RHSA-2013:0192",{"_key":30},"RHSA-2013:0193",{"_key":32},"RHSA-2013:0195",{"_key":34},"RHSA-2013:0196",{"_key":36},"RHSA-2013:0197",[],[],"2012-12-05T17:00:00.000Z","2024-08-06T23:08:23.793Z","Modified",{"cisa_kev":43,"cisa_ransomware":43,"cisa_vendor":9,"epss_severity":44,"epss_score":45,"severity":44,"severity_score":46,"severity_version":47,"severity_source":48,"severity_vector":49,"severity_status":41},false,"high",0.46306,7.5,"v2.0","nvd","AV:N/AC:L/Au:N/C:P/I:P/A:P",[51,58,65,70,74,78,82,87,91,97,101,105,109,113,117,121,125,131,135,139,144,148,152,156],{"url":52,"sources":53,"tags":55},"http://support.springsource.com/security/cve-2011-2730",[54,48],"cve.org",[56,57],"X Refsource CONFIRM","Vendor Advisory",{"url":59,"sources":60,"tags":62},"http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=677814",[54,48,61],"osv_maven",[63,64],"X Refsource MISC","WEB",{"url":66,"sources":67,"tags":68},"http://rhn.redhat.com/errata/RHSA-2013-0192.html",[54,48,61],[57,69,64],"X Refsource REDHAT",{"url":71,"sources":72,"tags":73},"http://rhn.redhat.com/errata/RHSA-2013-0198.html",[54,48,61],[57,69,64],{"url":75,"sources":76,"tags":77},"http://rhn.redhat.com/errata/RHSA-2013-0195.html",[54,48,61],[57,69,64],{"url":79,"sources":80,"tags":81},"http://rhn.redhat.com/errata/RHSA-2013-0221.html",[54,48,61],[57,69,64],{"url":83,"sources":84,"tags":85},"http://www.debian.org/security/2012/dsa-2504",[54,48,61],[57,86,64],"X Refsource DEBIAN",{"url":88,"sources":89,"tags":90},"http://rhn.redhat.com/errata/RHSA-2013-0196.html",[54,48,61],[57,69,64],{"url":92,"sources":93,"tags":94},"http://secunia.com/advisories/55155",[54,48],[95,96],"Third Party Advisory","X Refsource SECUNIA",{"url":98,"sources":99,"tags":100},"http://rhn.redhat.com/errata/RHSA-2013-0193.html",[54,48],[57,69],{"url":102,"sources":103,"tags":104},"http://secunia.com/advisories/51984",[54,48],[95,96],{"url":106,"sources":107,"tags":108},"http://secunia.com/advisories/52054",[54,48],[95,96],{"url":110,"sources":111,"tags":112},"http://rhn.redhat.com/errata/RHSA-2013-0191.html",[54,48,61],[57,69,64],{"url":114,"sources":115,"tags":116},"http://rhn.redhat.com/errata/RHSA-2013-0533.html",[54,48,61],[57,69,64],{"url":118,"sources":119,"tags":120},"http://rhn.redhat.com/errata/RHSA-2013-0197.html",[54,48],[57,69],{"url":122,"sources":123,"tags":124},"http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html",[54,48,61],[56,64],{"url":126,"sources":127,"tags":128},"http://www.securitytracker.com/id/1029151",[54,48],[129,130],"VDB Entry","X Refsource SECTRACK",{"url":132,"sources":133,"tags":134},"http://rhn.redhat.com/errata/RHSA-2013-0194.html",[54,48,61],[57,69,64],{"url":136,"sources":137,"tags":138},"https://docs.google.com/document/d/1dc1xxO8UMFaGLOwgkykYdghGWm_2Gn0iCrxFsympqcE/edit",[54,48,61],[63,64],{"url":140,"sources":141,"tags":142},"https://nvd.nist.gov/vuln/detail/CVE-2011-2730",[61],[143],"Advisory",{"url":145,"sources":146,"tags":147},"https://github.com/spring-projects/spring-framework/commit/62ccc8dd7e645fb91705d44919abac838cb5ca3f",[61],[64],{"url":149,"sources":150,"tags":151},"https://github.com/spring-projects/spring-framework/commit/9772eb8410e37cd0bdec0d1b133218446c778beb",[61],[64],{"url":153,"sources":154,"tags":155},"https://github.com/spring-projects/spring-framework/commit/b8d86330d1fadc645630416c3aaebf131bf749fc",[61],[64],{"url":157,"sources":158,"tags":159},"https://github.com/spring-projects/spring-framework",[61],[160],"PACKAGE",[],{"date":163,"score":45,"percentile":164},"2026-06-04",0.97712,[166,170,173,176,179,181,183,185,188,191,194,196,198,200,202,205,208,211,215,218,221,223,225,227,230,233,235,237,240,242,245,247,249,251,253,255,257,259,262,265,268,271,273,276,279,282,284,286,288,290,293,295,298,300,302,304,306,308,311,314,316,318,321,324,326,328,330,332,334,336,338,340,343,346,349,351,353,356,359,361,364,367,370,372,374,376,378,381,383,386],{"date":167,"score":168,"percentile":169},"2025-11-04",0.53573,0.97853,{"date":171,"score":168,"percentile":172},"2025-11-05",0.97854,{"date":174,"score":168,"percentile":175},"2025-11-06",0.97855,{"date":177,"score":168,"percentile":178},"2025-11-07",0.97856,{"date":180,"score":168,"percentile":178},"2025-11-08",{"date":182,"score":168,"percentile":178},"2025-11-09",{"date":184,"score":168,"percentile":178},"2025-11-10",{"date":186,"score":168,"percentile":187},"2025-11-11",0.97857,{"date":189,"score":168,"percentile":190},"2025-11-12",0.9786,{"date":192,"score":168,"percentile":193},"2025-11-13",0.97861,{"date":195,"score":168,"percentile":193},"2025-11-14",{"date":197,"score":168,"percentile":187},"2025-11-15",{"date":199,"score":168,"percentile":187},"2025-11-16",{"date":201,"score":168,"percentile":187},"2025-11-17",{"date":203,"score":168,"percentile":204},"2025-11-18",0.97886,{"date":206,"score":168,"percentile":207},"2025-11-19",0.97887,{"date":209,"score":168,"percentile":210},"2025-11-20",0.97889,{"date":212,"score":213,"percentile":214},"2025-11-21",0.54142,0.97883,{"date":216,"score":213,"percentile":217},"2025-11-22",0.97882,{"date":219,"score":213,"percentile":220},"2025-11-23",0.97881,{"date":222,"score":213,"percentile":220},"2025-11-24",{"date":224,"score":213,"percentile":217},"2025-11-25",{"date":226,"score":213,"percentile":217},"2025-11-26",{"date":228,"score":213,"percentile":229},"2025-11-27",0.97884,{"date":231,"score":213,"percentile":232},"2025-11-28",0.97885,{"date":234,"score":213,"percentile":204},"2025-11-29",{"date":236,"score":213,"percentile":232},"2025-11-30",{"date":238,"score":213,"percentile":239},"2025-12-01",0.97902,{"date":241,"score":213,"percentile":239},"2025-12-02",{"date":243,"score":213,"percentile":244},"2025-12-03",0.97901,{"date":246,"score":168,"percentile":175},"2025-12-04",{"date":248,"score":168,"percentile":175},"2025-12-05",{"date":250,"score":168,"percentile":187},"2025-12-06",{"date":252,"score":168,"percentile":187},"2025-12-07",{"date":254,"score":168,"percentile":187},"2025-12-08",{"date":256,"score":168,"percentile":187},"2025-12-09",{"date":258,"score":168,"percentile":193},"2025-12-10",{"date":260,"score":168,"percentile":261},"2025-12-11",0.97863,{"date":263,"score":168,"percentile":264},"2025-12-12",0.97866,{"date":266,"score":168,"percentile":267},"2025-12-13",0.97867,{"date":269,"score":168,"percentile":270},"2025-12-14",0.97868,{"date":272,"score":168,"percentile":267},"2025-12-15",{"date":274,"score":168,"percentile":275},"2025-12-16",0.9787,{"date":277,"score":168,"percentile":278},"2025-12-17",0.97873,{"date":280,"score":168,"percentile":281},"2025-12-18",0.97872,{"date":283,"score":168,"percentile":278},"2025-12-19",{"date":285,"score":168,"percentile":275},"2025-12-20",{"date":287,"score":168,"percentile":275},"2025-12-21",{"date":289,"score":168,"percentile":270},"2025-12-22",{"date":291,"score":168,"percentile":292},"2025-12-23",0.97869,{"date":294,"score":168,"percentile":275},"2025-12-24",{"date":296,"score":168,"percentile":297},"2025-12-25",0.97871,{"date":299,"score":168,"percentile":297},"2025-12-26",{"date":301,"score":168,"percentile":229},"2025-12-27",{"date":303,"score":168,"percentile":292},"2025-12-28",{"date":305,"score":168,"percentile":281},"2025-12-29",{"date":307,"score":168,"percentile":281},"2025-12-30",{"date":309,"score":168,"percentile":310},"2025-12-31",0.97874,{"date":312,"score":168,"percentile":313},"2026-01-01",0.97897,{"date":315,"score":168,"percentile":313},"2026-01-02",{"date":317,"score":168,"percentile":313},"2026-01-03",{"date":319,"score":168,"percentile":320},"2026-01-04",0.97879,{"date":322,"score":168,"percentile":323},"2026-01-05",0.9788,{"date":325,"score":168,"percentile":220},"2026-01-06",{"date":327,"score":168,"percentile":217},"2026-01-07",{"date":329,"score":168,"percentile":217},"2026-01-08",{"date":331,"score":168,"percentile":232},"2026-01-09",{"date":333,"score":168,"percentile":204},"2026-01-10",{"date":335,"score":168,"percentile":229},"2026-01-11",{"date":337,"score":168,"percentile":232},"2026-01-12",{"date":339,"score":168,"percentile":204},"2026-01-13",{"date":341,"score":168,"percentile":342},"2026-01-14",0.9789,{"date":344,"score":168,"percentile":345},"2026-01-15",0.97892,{"date":347,"score":168,"percentile":348},"2026-01-16",0.97894,{"date":350,"score":168,"percentile":313},"2026-01-17",{"date":352,"score":168,"percentile":348},"2026-01-18",{"date":354,"score":213,"percentile":355},"2026-01-19",0.97925,{"date":357,"score":213,"percentile":358},"2026-01-20",0.97927,{"date":360,"score":213,"percentile":358},"2026-01-21",{"date":362,"score":213,"percentile":363},"2026-01-22",0.97928,{"date":365,"score":213,"percentile":366},"2026-01-23",0.97932,{"date":368,"score":213,"percentile":369},"2026-01-24",0.97933,{"date":371,"score":213,"percentile":366},"2026-01-25",{"date":373,"score":213,"percentile":369},"2026-01-26",{"date":375,"score":213,"percentile":369},"2026-01-27",{"date":377,"score":213,"percentile":369},"2026-01-28",{"date":379,"score":213,"percentile":380},"2026-01-29",0.97934,{"date":382,"score":213,"percentile":380},"2026-01-30",{"date":384,"score":213,"percentile":385},"2026-01-31",0.97931,{"date":387,"score":168,"percentile":388},"2026-02-01",0.97923,[390],{"source":48,"cvss_v2_0":391,"cvss_v3_0":9,"cvss_v3_1":9,"cvss_v4_0":9},{"baseScore":46,"baseSeverity":9,"vectorString":49,"impactScore":392,"exploitabilityScore":393},6.4,10,[395,417],{"ecosystem":396,"name":397,"vendor":398,"product":399,"cpe_part":9,"purl_type":400,"purl_namespace":398,"purl_name":399,"source":9,"versions":401},"Maven","org.springframework:spring-core","org.springframework","spring-core","maven",[402,410,413],{"version":403,"is_range":404,"range_type":405,"version_start":406,"version_start_type":407,"version_end":408,"version_end_type":409,"fixed_in":9},"gte3_0_0_lt3_0_6",true,"ecosystem","3.0.0","including","3.0.6","excluding",{"version":411,"is_range":404,"range_type":405,"version_start":9,"version_start_type":9,"version_end":412,"version_end_type":409,"fixed_in":9},"lt2_5_6_SEC03","2.5.6.SEC03",{"version":414,"is_range":404,"range_type":405,"version_start":415,"version_start_type":407,"version_end":416,"version_end_type":409,"fixed_in":9},"gte2_5_7_SR0_lt2_5_7_SR023","2.5.7.SR0","2.5.7.SR023",{"ecosystem":9,"name":418,"vendor":419,"product":420,"cpe_part":421,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":422},"spring framework","springsource","spring_framework","a",[423,427,430,432,434,436,438,440,442,444,446,448,450,451,453,455,457],{"version":424,"is_range":404,"range_type":425,"version_start":9,"version_start_type":9,"version_end":426,"version_end_type":407,"fixed_in":9},"lte2.5.7_sr01","cpe","2.5.7_sr01",{"version":428,"is_range":404,"range_type":425,"version_start":9,"version_start_type":9,"version_end":429,"version_end_type":407,"fixed_in":9},"lte3.0.5","3.0.5",{"version":431,"is_range":43,"range_type":425,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"2.5.0",{"version":433,"is_range":43,"range_type":425,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"2.5.0:rc1",{"version":435,"is_range":43,"range_type":425,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"2.5.0:rc2",{"version":437,"is_range":43,"range_type":425,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"2.5.1",{"version":439,"is_range":43,"range_type":425,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"2.5.2",{"version":441,"is_range":43,"range_type":425,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"2.5.3",{"version":443,"is_range":43,"range_type":425,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"2.5.4",{"version":445,"is_range":43,"range_type":425,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"2.5.5",{"version":447,"is_range":43,"range_type":425,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"2.5.6",{"version":449,"is_range":43,"range_type":425,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"2.5.7",{"version":406,"is_range":43,"range_type":425,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},{"version":452,"is_range":43,"range_type":425,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"3.0.1",{"version":454,"is_range":43,"range_type":425,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"3.0.2",{"version":456,"is_range":43,"range_type":425,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"3.0.3",{"version":458,"is_range":43,"range_type":425,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"3.0.4"]