QID 984160
QID 984160: Java (maven) Security Update for org.springframework.cloud:spring-cloud-function-core (GHSA-6v73-fgf6-w5j7)
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-6v73-fgf6-w5j7 for updates pertaining to this vulnerability.
Vendor References
- GHSA-6v73-fgf6-w5j7 -
github.com/advisories/GHSA-6v73-fgf6-w5j7
CVEs related to QID 984160
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-6v73-fgf6-w5j7 | org.springframework.cloud:spring-cloud-function-core |
|