QID 981330
QID 981330: Java (maven) Security Update for org.springframework:spring-core (GHSA-45vg-2v73-vm62)
The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-45vg-2v73-vm62 for updates pertaining to this vulnerability.
Vendor References
- GHSA-45vg-2v73-vm62 -
github.com/advisories/GHSA-45vg-2v73-vm62
CVEs related to QID 981330
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-45vg-2v73-vm62 | org.springframework:spring-core |
|