Follow

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use
Contact

Does application Spring4Shell- CVE-2022-2296 vulnerable if using spring-plugin-core : 1.2.0?

Is the system affected by CVE-2022-2296 if it only uses spring-plugin-core from the mentioned impacted list?

Configuration

  • java 8
  • Spring boot : 2.2.6.RELEASE
  • Packaged as executable JAR
  • spring-plugin-core : 1.2.0.RELEASE

MEDevel.com: Open-source for Healthcare and Education

Collecting and validating open-source software for healthcare, education, enterprise, development, medical imaging, medical records, and digital pathology.

Visit Medevel

>Solution :

a quick search for Spring Boot 2.2.6.RELEASE shows the maven repository with all vulnerabilities listed:
https://mvnrepository.com/artifact/org.springframework.boot/spring-boot/2.2.6.RELEASE

Add a comment

Leave a Reply

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use

Discover more from Dev solutions

Subscribe now to keep reading and get access to the full archive.

Continue reading