i2b2 / i2b2-workinggroup-transmart-etl

6 stars 2 forks source link

Vmware Spring: CVE-2022-22965: Spring Framework RCE via Data Binding used in i2b2.war #3

Open siddharthsatyakam opened 2 years ago

siddharthsatyakam commented 2 years ago

the Rapid7 vunerability scanner is finding

Vulnerable software installed: VMware Spring Beans 5.1.8 in diff/opt/jboss/i2b2-core-server/edu.harvard.i2b2.server-common/dist/i2b2.war; but we were not able to find any commits resolving the same.

Could you please help us with the same??