Логотип exploitDog
bind:CVE-2021-37694
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-37694

Количество 2

Количество 2

nvd логотип

CVE-2021-37694

больше 4 лет назад

@asyncapi/java-spring-cloud-stream-template generates a Spring Cloud Stream (SCSt) microservice. In versions prior to 0.7.0 arbitrary code injection was possible when an attacker controls the AsyncAPI document. An example is provided in GHSA-xj6r-2jpm-qvxp. There are no mitigations available and all users are advised to update.

CVSS3: 8.7
EPSS: Низкий
github логотип

GHSA-xj6r-2jpm-qvxp

больше 4 лет назад

Code injection issue for java-spring-cloud-stream-template

CVSS3: 8.7
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-37694

@asyncapi/java-spring-cloud-stream-template generates a Spring Cloud Stream (SCSt) microservice. In versions prior to 0.7.0 arbitrary code injection was possible when an attacker controls the AsyncAPI document. An example is provided in GHSA-xj6r-2jpm-qvxp. There are no mitigations available and all users are advised to update.

CVSS3: 8.7
0%
Низкий
больше 4 лет назад
github логотип
GHSA-xj6r-2jpm-qvxp

Code injection issue for java-spring-cloud-stream-template

CVSS3: 8.7
0%
Низкий
больше 4 лет назад

Уязвимостей на страницу