VDB
EN
HIGH 8.6

GHSA-whpp-xv3h-rwxf

Spring Web Services: SSRF via unvalidated WS-Addressing reply destinations

빠른 조치

GHSA-whpp-xv3h-rwxf — org.springframework.ws:spring-ws-core: 아래 명령으로 수정 버전으로 올리세요.

# pom.xml: bump <version>5.0.2</version> for org.springframework.ws:spring-ws-core

상세

When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServiceMessageSender instances to destinations taken directly from request headers without verifying that those destinations are safe to connect to.

Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.

이 버전이 영향받나요?

사용 중인 패키지 버전을 입력하면 즉시 평가합니다.

영향 패키지

Maven / org.springframework.ws:spring-ws-core
최초 영향 버전: 5.0.0 수정 버전: 5.0.2
수정 # pom.xml: bump <version>5.0.2</version> for org.springframework.ws:spring-ws-core
Maven / org.springframework.ws:spring-ws-core
최초 영향 버전: 4.1.0 수정 버전: 4.1.4
수정 # pom.xml: bump <version>4.1.4</version> for org.springframework.ws:spring-ws-core
Maven / org.springframework.ws:spring-ws-core
최초 영향 버전: 4.0.0

No fixed version published yet for org.springframework.ws:spring-ws-core (maven). Pin to a known-safe version or switch to an alternative.

Maven / org.springframework.ws:spring-ws-core
최초 영향 버전: 3.1.0

No fixed version published yet for org.springframework.ws:spring-ws-core (maven). Pin to a known-safe version or switch to an alternative.

참고