[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2023-20860":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T08:55:32.481Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":18,"aliases":19,"duplicate_of":9,"upstream":21,"downstream":22,"duplicates":37,"related":38,"reserved_at":9,"published_at":39,"modified_at":40,"state":41,"summary":42,"references_raw":51,"kevs":82,"epss":83,"epss_history":86,"metrics":318,"affected":331},"CVE-2023-20860","Spring Framework running version 6.0.0 - 6.0.6 or 5.3.0 - 5.3.25 using \"**\" as a pattern in Spring Security configuration with the mvcRequestMatcher creates a mismatch in pattern matching between Spring Security and Spring MVC, and the potential for a security bypass.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":9,"likelihood_of_exploit":9,"capec":17},"NVD-CWE-NOINFO","Insufficient Information","NVD uses this CWE ID when there is insufficient information to assign a specific CWE.","placeholder","NVD-Reserved",[],[],[20],"GHSA-7phw-cxx7-q9vq",[],[23,25,27,29,31,33,35],{"_key":24},"RHSA-2023:3771",{"_key":26},"RHSA-2023:3622",{"_key":28},"DEBIAN-CVE-2023-20860",{"_key":30},"RHSA-2023:3625",{"_key":32},"RHSA-2023:3663",{"_key":34},"UBUNTU-CVE-2023-20860",{"_key":36},"RHSA-2023:3610",[],[],"2023-03-27T00:00:00.000Z","2025-02-19T19:05:54.805Z","Modified",{"cisa_kev":43,"cisa_ransomware":43,"cisa_vendor":9,"epss_severity":44,"epss_score":45,"severity":46,"severity_score":47,"severity_version":48,"severity_source":49,"severity_vector":50,"severity_status":41},false,"critical",0.56284,"high",7.5,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",[52,60,64,69,73,78],{"url":53,"sources":54,"tags":57},"https://spring.io/security/cve-2023-20860",[49,55,56],"nvd","osv_maven",[58,59],"Vendor Advisory","WEB",{"url":61,"sources":62,"tags":63},"https://security.netapp.com/advisory/ntap-20230505-0006/",[49,55],[],{"url":65,"sources":66,"tags":67},"https://nvd.nist.gov/vuln/detail/CVE-2023-20860",[56],[68],"Advisory",{"url":70,"sources":71,"tags":72},"https://github.com/spring-projects/spring-framework/commit/202fa5cdb3a3d0cfe6967e85fa167d978244f28a",[56],[59],{"url":74,"sources":75,"tags":76},"https://github.com/spring-projects/spring-framework",[56],[77],"PACKAGE",{"url":79,"sources":80,"tags":81},"https://security.netapp.com/advisory/ntap-20230505-0006",[56],[59],[],{"date":84,"score":45,"percentile":85},"2026-06-04",0.9815,[87,91,95,98,101,103,106,108,110,113,116,119,122,124,126,130,133,136,139,141,143,145,147,149,151,153,155,157,160,162,164,166,168,170,172,174,176,179,182,185,188,190,192,195,197,200,202,206,209,212,215,218,221,224,227,229,231,233,235,238,240,242,245,247,249,252,255,258,260,263,265,268,271,274,277,279,281,284,286,290,293,296,299,301,304,307,309,311,313,315],{"date":88,"score":89,"percentile":90},"2025-11-04",0.63306,0.98307,{"date":92,"score":93,"percentile":94},"2025-11-05",0.53491,0.97848,{"date":96,"score":93,"percentile":97},"2025-11-06",0.97849,{"date":99,"score":93,"percentile":100},"2025-11-07",0.97851,{"date":102,"score":93,"percentile":100},"2025-11-08",{"date":104,"score":93,"percentile":105},"2025-11-09",0.9785,{"date":107,"score":93,"percentile":105},"2025-11-10",{"date":109,"score":93,"percentile":100},"2025-11-11",{"date":111,"score":93,"percentile":112},"2025-11-12",0.97854,{"date":114,"score":93,"percentile":115},"2025-11-13",0.97855,{"date":117,"score":93,"percentile":118},"2025-11-14",0.97856,{"date":120,"score":93,"percentile":121},"2025-11-15",0.97852,{"date":123,"score":93,"percentile":121},"2025-11-16",{"date":125,"score":93,"percentile":121},"2025-11-17",{"date":127,"score":128,"percentile":129},"2025-11-18",0.62896,0.98366,{"date":131,"score":128,"percentile":132},"2025-11-19",0.98367,{"date":134,"score":128,"percentile":135},"2025-11-20",0.98369,{"date":137,"score":93,"percentile":138},"2025-11-21",0.97853,{"date":140,"score":93,"percentile":100},"2025-11-22",{"date":142,"score":93,"percentile":105},"2025-11-23",{"date":144,"score":93,"percentile":100},"2025-11-24",{"date":146,"score":93,"percentile":121},"2025-11-25",{"date":148,"score":93,"percentile":121},"2025-11-26",{"date":150,"score":93,"percentile":138},"2025-11-27",{"date":152,"score":93,"percentile":112},"2025-11-28",{"date":154,"score":93,"percentile":115},"2025-11-29",{"date":156,"score":93,"percentile":112},"2025-11-30",{"date":158,"score":93,"percentile":159},"2025-12-01",0.97871,{"date":161,"score":93,"percentile":159},"2025-12-02",{"date":163,"score":93,"percentile":159},"2025-12-03",{"date":165,"score":93,"percentile":138},"2025-12-04",{"date":167,"score":93,"percentile":121},"2025-12-05",{"date":169,"score":93,"percentile":112},"2025-12-06",{"date":171,"score":93,"percentile":112},"2025-12-07",{"date":173,"score":93,"percentile":115},"2025-12-08",{"date":175,"score":93,"percentile":112},"2025-12-09",{"date":177,"score":93,"percentile":178},"2025-12-10",0.97858,{"date":180,"score":93,"percentile":181},"2025-12-11",0.97861,{"date":183,"score":93,"percentile":184},"2025-12-12",0.97864,{"date":186,"score":93,"percentile":187},"2025-12-13",0.97865,{"date":189,"score":93,"percentile":187},"2025-12-14",{"date":191,"score":93,"percentile":187},"2025-12-15",{"date":193,"score":93,"percentile":194},"2025-12-16",0.97868,{"date":196,"score":93,"percentile":159},"2025-12-17",{"date":198,"score":93,"percentile":199},"2025-12-18",0.97869,{"date":201,"score":93,"percentile":199},"2025-12-19",{"date":203,"score":204,"percentile":205},"2025-12-20",0.55048,0.97946,{"date":207,"score":204,"percentile":208},"2025-12-21",0.97945,{"date":210,"score":204,"percentile":211},"2025-12-22",0.97939,{"date":213,"score":204,"percentile":214},"2025-12-23",0.97943,{"date":216,"score":204,"percentile":217},"2025-12-24",0.97944,{"date":219,"score":204,"percentile":220},"2025-12-25",0.9794,{"date":222,"score":204,"percentile":223},"2025-12-26",0.97941,{"date":225,"score":204,"percentile":226},"2025-12-27",0.97955,{"date":228,"score":204,"percentile":223},"2025-12-28",{"date":230,"score":204,"percentile":217},"2025-12-29",{"date":232,"score":204,"percentile":214},"2025-12-30",{"date":234,"score":204,"percentile":208},"2025-12-31",{"date":236,"score":204,"percentile":237},"2026-01-01",0.9797,{"date":239,"score":204,"percentile":237},"2026-01-02",{"date":241,"score":204,"percentile":237},"2026-01-03",{"date":243,"score":204,"percentile":244},"2026-01-04",0.97953,{"date":246,"score":204,"percentile":226},"2026-01-05",{"date":248,"score":204,"percentile":226},"2026-01-06",{"date":250,"score":204,"percentile":251},"2026-01-07",0.97957,{"date":253,"score":204,"percentile":254},"2026-01-08",0.97958,{"date":256,"score":204,"percentile":257},"2026-01-09",0.97961,{"date":259,"score":204,"percentile":257},"2026-01-10",{"date":261,"score":204,"percentile":262},"2026-01-11",0.97959,{"date":264,"score":204,"percentile":262},"2026-01-12",{"date":266,"score":204,"percentile":267},"2026-01-13",0.9796,{"date":269,"score":204,"percentile":270},"2026-01-14",0.97963,{"date":272,"score":204,"percentile":273},"2026-01-15",0.97965,{"date":275,"score":204,"percentile":276},"2026-01-16",0.97967,{"date":278,"score":204,"percentile":237},"2026-01-17",{"date":280,"score":204,"percentile":276},"2026-01-18",{"date":282,"score":204,"percentile":283},"2026-01-19",0.97969,{"date":285,"score":204,"percentile":237},"2026-01-20",{"date":287,"score":288,"percentile":289},"2026-01-21",0.56363,0.98032,{"date":291,"score":288,"percentile":292},"2026-01-22",0.98034,{"date":294,"score":288,"percentile":295},"2026-01-23",0.98036,{"date":297,"score":288,"percentile":298},"2026-01-24",0.98037,{"date":300,"score":288,"percentile":295},"2026-01-25",{"date":302,"score":288,"percentile":303},"2026-01-26",0.98038,{"date":305,"score":288,"percentile":306},"2026-01-27",0.98039,{"date":308,"score":288,"percentile":306},"2026-01-28",{"date":310,"score":288,"percentile":303},"2026-01-29",{"date":312,"score":288,"percentile":303},"2026-01-30",{"date":314,"score":288,"percentile":289},"2026-01-31",{"date":316,"score":288,"percentile":317},"2026-02-01",0.98051,[319,324,326],{"source":49,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":320,"cvss_v4_0":9},{"baseScore":47,"baseSeverity":321,"vectorString":50,"impactScore":322,"exploitabilityScore":323},"HIGH",6,10,{"source":55,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":325,"cvss_v4_0":9},{"baseScore":47,"baseSeverity":321,"vectorString":50,"impactScore":322,"exploitabilityScore":323},{"source":56,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":327,"cvss_v4_0":9},{"baseScore":328,"baseSeverity":9,"vectorString":329,"impactScore":330,"exploitabilityScore":323},9.1,"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N",8.7,[332,351,357],{"ecosystem":333,"name":334,"vendor":335,"product":336,"cpe_part":9,"purl_type":337,"purl_namespace":335,"purl_name":336,"source":9,"versions":338},"Maven","org.springframework:spring","org.springframework","spring","maven",[339,347],{"version":340,"is_range":341,"range_type":342,"version_start":343,"version_start_type":344,"version_end":345,"version_end_type":346,"fixed_in":9},"gte6_0_0_lt6_0_7",true,"ecosystem","6.0.0","including","6.0.7","excluding",{"version":348,"is_range":341,"range_type":342,"version_start":349,"version_start_type":344,"version_end":350,"version_end_type":346,"fixed_in":9},"gte5_3_0_lt5_3_26","5.3.0","5.3.26",{"ecosystem":333,"name":352,"vendor":335,"product":353,"cpe_part":9,"purl_type":337,"purl_namespace":335,"purl_name":353,"source":9,"versions":354},"org.springframework:spring-webmvc","spring-webmvc",[355,356],{"version":340,"is_range":341,"range_type":342,"version_start":343,"version_start_type":344,"version_end":345,"version_end_type":346,"fixed_in":9},{"version":348,"is_range":341,"range_type":342,"version_start":349,"version_start_type":344,"version_end":350,"version_end_type":346,"fixed_in":9},{"ecosystem":9,"name":358,"vendor":9,"product":358,"cpe_part":9,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":359},"Spring Framework",[360,363],{"version":361,"is_range":341,"range_type":362,"version_start":349,"version_start_type":344,"version_end":350,"version_end_type":346,"fixed_in":9},"gte5.3.0_lt5.3.26","cpe",{"version":364,"is_range":341,"range_type":362,"version_start":343,"version_start_type":344,"version_end":345,"version_end_type":346,"fixed_in":9},"gte6.0.0_lt6.0.7"]