From 2d1e6d0a90b1aff9b0ba792559262eeff572b4b9 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Fri, 31 Jan 2025 19:04:59 +0000 Subject: [PATCH] Publish GHSA-3rmv-2pg5-xvqj --- .../GHSA-3rmv-2pg5-xvqj.json | 30 ++++++++----------- 1 file changed, 13 insertions(+), 17 deletions(-) diff --git a/advisories/github-reviewed/2018/10/GHSA-3rmv-2pg5-xvqj/GHSA-3rmv-2pg5-xvqj.json b/advisories/github-reviewed/2018/10/GHSA-3rmv-2pg5-xvqj/GHSA-3rmv-2pg5-xvqj.json index 748f9974be3..a2e4f4b8d88 100644 --- a/advisories/github-reviewed/2018/10/GHSA-3rmv-2pg5-xvqj/GHSA-3rmv-2pg5-xvqj.json +++ b/advisories/github-reviewed/2018/10/GHSA-3rmv-2pg5-xvqj/GHSA-3rmv-2pg5-xvqj.json @@ -1,12 +1,12 @@ { "schema_version": "1.4.0", "id": "GHSA-3rmv-2pg5-xvqj", - "modified": "2024-03-06T21:04:37Z", + "modified": "2025-01-31T19:03:33Z", "published": "2018-10-17T20:28:00Z", "aliases": [ "CVE-2018-1275" ], - "summary": "Improperly Implemented Security Check for Standard in org.springframework:spring-core", + "summary": "Spring Framework has Improperly Implemented Security Check for Standard", "details": "Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.16 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack. This CVE addresses the partial fix for CVE-2018-1270 in the 4.3.x branch of the Spring Framework.", "severity": [ { @@ -28,7 +28,7 @@ "introduced": "0" }, { - "fixed": "4.3.16" + "fixed": "4.3.16.RELEASE" } ] } @@ -44,10 +44,10 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "5.0.0" + "introduced": "5.0.0.RELEASE" }, { - "fixed": "5.0.5" + "fixed": "5.0.5.RELEASE" } ] } @@ -75,10 +75,6 @@ "type": "WEB", "url": "https://access.redhat.com/errata/RHSA-2018:2939" }, - { - "type": "ADVISORY", - "url": "https://github.com/advisories/GHSA-3rmv-2pg5-xvqj" - }, { "type": "PACKAGE", "url": "https://github.com/spring-projects/spring-framework" @@ -99,6 +95,14 @@ "type": "WEB", "url": "https://pivotal.io/security/cve-2018-1275" }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20190901081835/http://www.securitytracker.com/id/1041301" + }, + { + "type": "WEB", + "url": "https://web.archive.org/web/20200227033125/http://www.securityfocus.com/bid/103771" + }, { "type": "WEB", "url": "https://www.oracle.com/security-alerts/cpujul2020.html" @@ -122,14 +126,6 @@ { "type": "WEB", "url": "http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html" - }, - { - "type": "WEB", - "url": "http://www.securityfocus.com/bid/103771" - }, - { - "type": "WEB", - "url": "http://www.securitytracker.com/id/1041301" } ], "database_specific": {