CVE-2023-20873: VMware Spring Boot
Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.
In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susceptible to a security bypass. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.6+. 2.7.x users should upgrade to 2.7.11+. Users of older, unsupported versions should upgrade to 3.0.6+ or 2.7.11+.
Affected products
- VMware Spring Boot: before 2.5.15 (fixed in 2.5.15); from 2.6.0, before 2.6.14 (fixed in 2.6.14); from 2.7.0, before 2.7.11 (fixed in 2.7.11); from 3.0.0, before 3.0.6 (fixed in 3.0.6)
Published 2023-04-20. Last modified 2026-06-17.