VYPR

Tools for Eclipse

by Spring Projects

CVEs (4)

  • CVE-2026-47858HigJul 30, 2026
    risk 0.52cvss 8.0epss 0.00

    Starting Spring Boot applications in the Spring Tools with the live information mode enabled makes the running application vulnerable against JMX-based remote code execution. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier Spring Tools for…

  • CVE-2026-59327MedJul 30, 2026
    risk 0.00cvss 4.4epss 0.00

    Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain string attribute on the "Spring Boot DevTools Client" launch configuration. Eclipse persists launch configuration attributes as cleartext XML, either to workspace…

  • CVE-2026-47882HigJul 30, 2026
    risk 0.00cvss 8.3epss 0.00

    When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools Boot Dashboard, Spring Tools generates a shared secret that authenticates DevTools remote-restart uploads to the deployed…

  • CVE-2026-47873HigJul 30, 2026
    risk 0.00cvss 8.0epss 0.00

    The Boot Dashboard Docker integration in Spring Tools publishes container control ports on all of the host's network interfaces (0.0.0.0) rather than restricting them to loopback. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier