Publish GHSA-3rmv-2pg5-xvqj

This commit is contained in:
advisory-database[bot]
2025-01-31 19:04:59 +00:00
parent 3aeb57aa54
commit 2d1e6d0a90
@@ -1,12 +1,12 @@
{
"schema_version": "1.4.0",
"id": "GHSA-3rmv-2pg5-xvqj",
"modified": "2024-03-06T21:04:37Z",
"modified": "2025-01-31T19:03:33Z",
"published": "2018-10-17T20:28:00Z",
"aliases": [
"CVE-2018-1275"
],
"summary": "Improperly Implemented Security Check for Standard in org.springframework:spring-core",
"summary": "Spring Framework has Improperly Implemented Security Check for Standard",
"details": "Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for CVE-2018-1270 in the 4.3.x branch of the Spring Framework.",
"severity": [
{
@@ -28,7 +28,7 @@
"introduced": "0"
},
{
"fixed": "4.3.16"
"fixed": "4.3.16.RELEASE"
}
]
}
@@ -44,10 +44,10 @@
"type": "ECOSYSTEM",
"events": [
{
"introduced": "5.0.0"
"introduced": "5.0.0.RELEASE"
},
{
"fixed": "5.0.5"
"fixed": "5.0.5.RELEASE"
}
]
}
@@ -75,10 +75,6 @@
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2018:2939"
},
{
"type": "ADVISORY",
"url": "https://github.com/advisories/GHSA-3rmv-2pg5-xvqj"
},
{
"type": "PACKAGE",
"url": "https://github.com/spring-projects/spring-framework"
@@ -99,6 +95,14 @@
"type": "WEB",
"url": "https://pivotal.io/security/cve-2018-1275"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20190901081835/http://www.securitytracker.com/id/1041301"
},
{
"type": "WEB",
"url": "https://web.archive.org/web/20200227033125/http://www.securityfocus.com/bid/103771"
},
{
"type": "WEB",
"url": "https://www.oracle.com/security-alerts/cpujul2020.html"
@@ -122,14 +126,6 @@
{
"type": "WEB",
"url": "http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/103771"
},
{
"type": "WEB",
"url": "http://www.securitytracker.com/id/1041301"
}
],
"database_specific": {