Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9qf9-28h9-hqcj

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Remote code execution in PATCH requests in Spring Data REST

Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) can use specially crafted JSON data to run arbitrary Java code.

Пакеты

Наименование

org.springframework.data:spring-data-rest-core

maven
Затронутые версииВерсия исправления

< 2.6.9.RELEASE

2.6.9.RELEASE

Наименование

org.springframework.data:spring-data-rest-core

maven
Затронутые версииВерсия исправления

>= 3.0.0, < 3.0.1.RELEASE

3.0.1.RELEASE

EPSS

Процентиль: 100%
0.93978
Критический

9.8 Critical

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 10
redhat
почти 8 лет назад

Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.

CVSS3: 9.8
nvd
около 8 лет назад

Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code.

EPSS

Процентиль: 100%
0.93978
Критический

9.8 Critical

CVSS3

Дефекты

CWE-20