gwhittemore-veracode / Veracode-GW-Training-demo

1 stars 0 forks source link

CVE: 2016-1000027 found in Spring Web - Version: 4.3.10.RELEASE [JAVA] #173

Open github-actions[bot] opened 1 year ago

github-actions[bot] commented 1 year ago

Veracode Software Composition Analysis

Attribute Details
Library Spring Web
Description Spring Web
Language JAVA
Vulnerability Remote Code Execution (RCE)
Vulnerability description spring-web is vulnerable to remote code execution (RCE). When it is used with external endpoints regardless of endpoints being authenticated or not, the function HttpInvokerServiceExporter: readRemoteInvocation allows deserialization of untrusted object if the endpoints are exposed to untrusted clients. It depends on the implementation within a product to mandate an authentication and to protect an application from an authenticated deserialization. The vendor has claimed the behavior to be as intended, but has deprecated the vulnerable Sun's JDK HTTP server classes in version 6.0.0.
CVE 2016-1000027
CVSS score 7.5
Vulnerability present in version/s 4.0.0.M1-5.3.26
Found library version/s 4.3.10.RELEASE
Vulnerability fixed in version 6.0.0
Library latest version 6.0.8
Fix

Links: