veracode-repository-ruleset / verademo-java-maven

verademo-java-maven
0 stars 0 forks source link

CVE: 2018-1199 found in Spring Web MVC - Version: 4.3.10.RELEASE [JAVA] #47

Open github-actions[bot] opened 8 months ago

github-actions[bot] commented 8 months ago

Veracode Software Composition Analysis

Attribute Details
Library Spring Web MVC
Description Spring Web MVC
Language JAVA
Vulnerability Security Constraint Bypass
Vulnerability description spring-security-web and spring-web are vulnerable to security bypass with static resources. Spring uses the output of getPathInfo() when mapping security constraints and requests. It is not standardized whether the path parameters should be included in the value from getPathInfo(). Using this knowledge, attackers can bypass security constraints by using encoded characters.
CVE 2018-1199
CVSS score 5
Vulnerability present in version/s 3.1.0.RELEASE-4.3.12.RELEASE
Found library version/s 4.3.10.RELEASE
Vulnerability fixed in version 4.3.13.RELEASE
Library latest version 6.1.1
Fix

Links:

github-actions[bot] commented 6 months ago

Veracode issue link to PR: https://github.com/veracode-repository-ruleset/verademo-java-maven/pull/54