Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g5h3-w546-pj7f

Опубликовано: 20 апр. 2023
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Spring Boot Security Bypass with Wildcard Pattern Matching on Cloud Foundry

In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susceptible to a security bypass. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.6+. 2.7.x users should upgrade to 2.7.11+. Users of older, unsupported versions should upgrade to 3.0.6+ or 2.7.11+.

Пакеты

Наименование

org.springframework.boot:spring-boot-actuator-autoconfigure

maven
Затронутые версииВерсия исправления

>= 3.0.0, < 3.0.6

3.0.6

Наименование

org.springframework.boot:spring-boot-actuator-autoconfigure

maven
Затронутые версииВерсия исправления

>= 2.7.0, < 2.7.11

2.7.11

Наименование

org.springframework.boot:spring-boot-actuator-autoconfigure

maven
Затронутые версииВерсия исправления

>= 2.6.0, < 2.6.15

2.6.15

Наименование

org.springframework.boot:spring-boot-actuator-autoconfigure

maven
Затронутые версииВерсия исправления

< 2.5.15

2.5.15

EPSS

Процентиль: 56%
0.00335
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
redhat
больше 2 лет назад

In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susceptible to a security bypass. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.6+. 2.7.x users should upgrade to 2.7.11+. Users of older, unsupported versions should upgrade to 3.0.6+ or 2.7.11+.

CVSS3: 9.8
nvd
почти 3 года назад

In Spring Boot versions 3.0.0 - 3.0.5, 2.7.0 - 2.7.10, and older unsupported versions, an application that is deployed to Cloud Foundry could be susceptible to a security bypass. Users of affected versions should apply the following mitigation: 3.0.x users should upgrade to 3.0.6+. 2.7.x users should upgrade to 2.7.11+. Users of older, unsupported versions should upgrade to 3.0.6+ or 2.7.11+.

EPSS

Процентиль: 56%
0.00335
Низкий

9.8 Critical

CVSS3