Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w3x5-427h-wfq6

Опубликовано: 09 дек. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

Spring Boot Admins integrated notifier support allows arbitrary code execution

Impact

All users who run Spring Boot Admin Server, having enabled Notifiers (e.g. Teams-Notifier) and write access to environment variables via UI are possibly affected.

Patches

In the most recent releases of Spring Boot Admin 2.6.10 and 2.7.8 the issue is fixed by implementing SimpleExecutionContext of SpEL. This prevents the arbitrary code execution (i.e. SpEL injection).

Workarounds

  • Disable any notifier
  • Disable write access (POST request) on /env actuator endpoint

Пакеты

Наименование

de.codecentric:spring-boot-admin

maven
Затронутые версииВерсия исправления

< 2.6.10

2.6.10

Наименование

de.codecentric:spring-boot-admin

maven
Затронутые версииВерсия исправления

>= 2.7.0, < 2.7.8

2.7.8

Наименование

de.codecentric:spring-boot-admin

maven
Затронутые версииВерсия исправления

>= 3.0.0-M1, < 3.0.0-M6

3.0.0-M6

EPSS

Процентиль: 96%
0.23368
Средний

8 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8
nvd
около 3 лет назад

Spring boot admins is an open source administrative user interface for management of spring boot applications. All users who run Spring Boot Admin Server, having enabled Notifiers (e.g. Teams-Notifier) and write access to environment variables via UI are affected. Users are advised to upgrade to the most recent releases of Spring Boot Admin 2.6.10 and 2.7.8 to resolve this issue. Users unable to upgrade may disable any notifier or disable write access (POST request) on `/env` actuator endpoint.

EPSS

Процентиль: 96%
0.23368
Средний

8 High

CVSS3

Дефекты

CWE-94