veracode-repository-ruleset / verademo-java-maven

verademo-java-maven
0 stars 0 forks source link

CVE: 2018-1272 found in Spring Core - Version: 4.3.10.RELEASE [JAVA] #42

Open github-actions[bot] opened 8 months ago

github-actions[bot] commented 8 months ago

Veracode Software Composition Analysis

Attribute Details
Library Spring Core
Description Spring Core
Language JAVA
Vulnerability Privilege Escalation Through Multipart Content Pollution
Vulnerability description spring-core is vulnerable to multipart content pollution. The application uses an insecure number generator to generate the multipart boundary parameter value, allowing a malicious user to make a informed guess the multipart boundary parameter value. A malicious user can potentially perform a privilege escalation attack by sending tampered requests to a server that the user does not have sufficient access control to.
CVE 2018-1272
CVSS score 6
Vulnerability present in version/s 4.2.0.RELEASE-4.3.14.RELEASE
Found library version/s 4.3.10.RELEASE
Vulnerability fixed in version 4.3.15.RELEASE
Library latest version 6.1.1
Fix

Links:

github-actions[bot] commented 6 months ago

Veracode issue link to PR: https://github.com/veracode-repository-ruleset/verademo-java-maven/pull/54