julz0815 / test-action

0 stars 1 forks source link

CVE: 2024-22243 found in Spring Web - Version: 4.3.10.RELEASE [JAVA] #1149

Open github-actions[bot] opened 1 month ago

github-actions[bot] commented 1 month ago

Veracode Software Composition Analysis

Attribute Details
Library Spring Web
Description Spring Web
Language JAVA
Vulnerability Server Side Request Forgery (SSRF)
Vulnerability description org.springframework:spring-web is vulnerable to Open Redirect. The vulnerability is due to insufficient validation checks of the host URL within UriComponentsBuilder.java. If an application utilizes the host validation checks, an attacker can perform an open redirect or Server-Side Request Forgery (SSRF) attack.
CVE 2024-22243
CVSS score 7.8
Vulnerability present in version/s 3.1.0.RC1-5.3.31
Found library version/s 4.3.10.RELEASE
Vulnerability fixed in version 5.3.32
Library latest version 6.2.0-RC1
Fix Please update to 5.3.32

Links: