QID 980770
QID 980770: Java (maven) Security Update for org.springframework.boot:spring-boot (GHSA-xx65-cc7g-9pfp)
Spring Boot supports an embedded launch script that can be used to easily run the application as a systemd or init.d linux service. The script included with Spring Boot 1.5.9 and earlier and 2.0.0.M1 through 2.0.0.M7 is susceptible to a symlink attack which allows the "run_user" to overwrite and take ownership of any file on the same system. In order to instigate the attack, the application must be installed as a service and the "run_user" requires shell access to the server. Spring Boot application that are not installed as a service, or are not using the embedded launch script are not susceptible.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-xx65-cc7g-9pfp for updates pertaining to this vulnerability.
Vendor References
- GHSA-xx65-cc7g-9pfp -
github.com/advisories/GHSA-xx65-cc7g-9pfp
CVEs related to QID 980770
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xx65-cc7g-9pfp | org.springframework.boot:spring-boot |
|