veracode-repository-ruleset / verademo-java-maven

verademo-java-maven
0 stars 0 forks source link

CVE: 2016-1000027 found in Spring Web - Version: 4.3.10.RELEASE [JAVA] #52

Open github-actions[bot] opened 8 months ago

github-actions[bot] commented 8 months ago

Veracode Software Composition Analysis

Attribute Details
Library Spring Web
Description Spring Web
Language JAVA
Vulnerability Remote Code Execution (RCE)
Vulnerability description spring-web is vulnerable to remote code execution (RCE). When it is used with external endpoints regardless of endpoints being authenticated or not, the function HttpInvokerServiceExporter: readRemoteInvocation allows deserialization of untrusted object if the endpoints are exposed to untrusted clients. It depends on the implementation within a product to mandate an authentication and to protect an application from an authenticated deserialization. The vendor has claimed the behavior to be as intended, but has deprecated the vulnerable Sun's JDK HTTP server classes in version 6.0.0.
CVE 2016-1000027
CVSS score 7.5
Vulnerability present in version/s 4.0.0.M1-5.3.31
Found library version/s 4.3.10.RELEASE
Vulnerability fixed in version 6.0.0
Library latest version 6.1.1
Fix

Links:

github-actions[bot] commented 6 months ago

Veracode issue link to PR: https://github.com/veracode-repository-ruleset/verademo-java-maven/pull/54