MEDIUM 5.0
GHSA-9wxp-w4px-32vh
Spring Boot's Mail Auto-Configuration Does Not Enable SSL Hostname Verification
빠른 조치
GHSA-9wxp-w4px-32vh — org.springframework.boot:spring-boot-starter-mail: 아래 명령으로 수정 버전으로 올리세요.
# pom.xml: bump <version>4.0.7</version> for org.springframework.boot:spring-boot-starter-mail 상세
Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail property, such as spring.mail.properties.mail.smtp.ssl.checkserveridentity=true, are not affected.
Affected versions: Spring Boot 4.0.0 through 4.0.6; 3.5.0 through 3.5.14; 3.4.0 through 3.4.16.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
Maven / org.springframework.boot:spring-boot-starter-mail
최초 영향 버전:
4.0.0 수정 버전: 4.0.7 수정
# pom.xml: bump <version>4.0.7</version> for org.springframework.boot:spring-boot-starter-mail Maven / org.springframework.boot:spring-boot-starter-mail
최초 영향 버전:
3.5.0 수정 버전: 3.5.15 수정
# pom.xml: bump <version>3.5.15</version> for org.springframework.boot:spring-boot-starter-mail Maven / org.springframework.boot:spring-boot-starter-mail
최초 영향 버전:
3.4.0 No fixed version published yet for org.springframework.boot:spring-boot-starter-mail (maven). Pin to a known-safe version or switch to an alternative.