Back Feeds.4Sysops Critical VMware Tanzu Spring flaws expose administrator access and isolated data
VMware Tanzu Spring software is facing a broad wave of security fixes, including a critical LDAP flaw that can grant administrator access and let attackers alter user identities. Additional weaknesses affect Spring Security, Spring AI, and Spring GraphQL, while CERT-Bund has separately reported multiple Spring Framework denial-of-service flaws rated CVSS 6.5; no exploitation has been confirmed so far. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
