Логотип exploitDog
bind:CVE-2022-46166
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-46166

Количество 2

Количество 2

nvd логотип

CVE-2022-46166

около 3 лет назад

Spring boot admins is an open source administrative user interface for management of spring boot applications. All users who run Spring Boot Admin Server, having enabled Notifiers (e.g. Teams-Notifier) and write access to environment variables via UI are affected. Users are advised to upgrade to the most recent releases of Spring Boot Admin 2.6.10 and 2.7.8 to resolve this issue. Users unable to upgrade may disable any notifier or disable write access (POST request) on `/env` actuator endpoint.

CVSS3: 8
EPSS: Средний
github логотип

GHSA-w3x5-427h-wfq6

около 3 лет назад

Spring Boot Admins integrated notifier support allows arbitrary code execution

CVSS3: 8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-46166

Spring boot admins is an open source administrative user interface for management of spring boot applications. All users who run Spring Boot Admin Server, having enabled Notifiers (e.g. Teams-Notifier) and write access to environment variables via UI are affected. Users are advised to upgrade to the most recent releases of Spring Boot Admin 2.6.10 and 2.7.8 to resolve this issue. Users unable to upgrade may disable any notifier or disable write access (POST request) on `/env` actuator endpoint.

CVSS3: 8
23%
Средний
около 3 лет назад
github логотип
GHSA-w3x5-427h-wfq6

Spring Boot Admins integrated notifier support allows arbitrary code execution

CVSS3: 8
23%
Средний
около 3 лет назад

Уязвимостей на страницу