QID 980026
QID 980026: Java (maven) Security Update for org.springframework.cloud:spring-cloud-netflix-hystrix-dashboard (GHSA-gx3f-hq7p-8fxv)
Applications using the `spring-cloud-netflix-hystrix-dashboard` expose a way to execute code submitted within the request URI path during the resolution of view templates. When a request is made at `/hystrix/monitor;[user-provided data]`, the path elements following `hystrix/monitor` are being evaluated as SpringEL expressions, which can lead to code execution.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-gx3f-hq7p-8fxv for updates pertaining to this vulnerability.
Vendor References
- GHSA-gx3f-hq7p-8fxv -
github.com/advisories/GHSA-gx3f-hq7p-8fxv
CVEs related to QID 980026
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-gx3f-hq7p-8fxv | org.springframework.cloud:spring-cloud-netflix-hystrix-dashboard |
|