Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-56v8-86gj-66jp

Опубликовано: 28 апр. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Spring Boot DevTools remote secret comparison is vulnerable to timing attacks

An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the attacker determining the secret and uploading changed classes, thereby achieving remote code execution in the remote application.

Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); DevTools remote secret comparison. Versions that are no longer supported are also affected per vendor advisory.

Пакеты

Наименование

org.springframework.boot:spring-boot-devtools

maven
Затронутые версииВерсия исправления

>= 4.0.0, < 4.0.6

4.0.6

Наименование

org.springframework.boot:spring-boot-devtools

maven
Затронутые версииВерсия исправления

>= 3.5.0, < 3.5.14

3.5.14

Наименование

org.springframework.boot:spring-boot-devtools

maven
Затронутые версииВерсия исправления

>= 3.4.0, <= 3.4.15

Отсутствует

Наименование

org.springframework.boot:spring-boot-devtools

maven
Затронутые версииВерсия исправления

>= 3.3.0, <= 3.3.18

Отсутствует

Наименование

org.springframework.boot:spring-boot-devtools

maven
Затронутые версииВерсия исправления

<= 2.7.32

Отсутствует

EPSS

Процентиль: 18%
0.00262
Низкий

7.5 High

CVSS3

Дефекты

CWE-208

Связанные уязвимости

CVSS3: 7.5
redhat
4 месяца назад

An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the attacker determining the secret and uploading changed classes, thereby achieving remote code execution in the remote application. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); DevTools remote secret comparison. Versions that are no longer supported are also affected per vendor advisory.

CVSS3: 7.5
nvd
4 месяца назад

An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the attacker determining the secret and uploading changed classes, thereby achieving remote code execution in the remote application. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); DevTools remote secret comparison. Versions that are no longer supported are also affected per vendor advisory.

EPSS

Процентиль: 18%
0.00262
Низкий

7.5 High

CVSS3

Дефекты

CWE-208