Vulnerabilities > Codecentric

DATE CVE VULNERABILITY TITLE RISK
2023-07-14 CVE-2023-38286 Command Injection vulnerability in multiple products
Thymeleaf through 3.1.1.RELEASE, as used in spring-boot-admin (aka Spring Boot Admin) through 3.1.1 and other products, allows sandbox bypass via crafted HTML.
network
high complexity
thymeleaf codecentric CWE-77
7.5
2022-12-09 CVE-2022-46166 Code Injection vulnerability in Codecentric Spring Boot Admin 3.0.0
Spring boot admins is an open source administrative user interface for management of spring boot applications.
network
low complexity
codecentric CWE-94
critical
9.8