Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

bump spring boot pga CVE #172

Merged
merged 1 commit into from
Jan 26, 2024
Merged

bump spring boot pga CVE #172

merged 1 commit into from
Jan 26, 2024

Conversation

kenglxn
Copy link
Contributor

@kenglxn kenglxn commented Jan 26, 2024

In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.

Specifically, an application is vulnerable when all of the following are true:

the application uses Spring MVC
Spring Security 6.1.6+ or 6.2.1+ is on the classpath
Typically, Spring Boot applications need the org.springframework.boot:spring-boot-starter-web and org.springframework.boot:spring-boot-starter-security dependencies to meet all conditions.

Sonatype's research suggests that this CVE's details differ from those defined at NVD. See https://ossindex.sonatype.org/vulnerability/CVE-2024-22233 for details

@kenglxn kenglxn requested a review from a team as a code owner January 26, 2024 09:58
@kenglxn kenglxn merged commit c690a33 into master Jan 26, 2024
3 checks passed
@kenglxn kenglxn deleted the bump_spring_boot branch January 26, 2024 10:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant