[Geoserver-devel] [JIRA] (GEOS-8695) High security vulnerability has been found in the Pivotal Spring Framework

Lukas Kosowski created an issue

GeoServer / BugGEOS-8695

High security vulnerability has been found in the Pivotal Spring Framework

Issue Type:

BugBug

Affects Versions:

2.13.0

Assignee:

Unassigned

Components:

Vulnerability

Created:

18/Apr/18 11:31 AM

Priority:

HighHigh

Reporter:

Lukas Kosowski

Spring Framework, versions 5.0.x prior to 5.0.5 and versions 4.3.x prior to 4.3.16, as well as older unsupported versions allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. [CVE-2018-1275]

https://pivotal.io/security/cve-2018-1275

Vendor Affected Components:
Spring Framework 5.0 ≤ 5.0.4
Spring Framework 4.3 ≤ 4.3.15
Older unsupported versions are also affected.

Add Comment

Add Comment

Get Jira notifications on your phone! Download the Jira Cloud app for Android or iOS


This message was sent by Atlassian Jira (v1001.0.0-SNAPSHOT#100082-sha1:507ddb9)

Atlassian logo