GHSA-whpp-xv3h-rwxf
Spring Web Services: SSRF via unvalidated WS-Addressing reply destinations
빠른 조치
GHSA-whpp-xv3h-rwxf — org.springframework.ws:spring-ws-core: 아래 명령으로 수정 버전으로 올리세요.
# pom.xml: bump <version>5.0.2</version> for org.springframework.ws:spring-ws-core 상세
When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServiceMessageSender instances to destinations taken directly from request headers without verifying that those destinations are safe to connect to.
Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
5.0.0 수정 버전: 5.0.2 # pom.xml: bump <version>5.0.2</version> for org.springframework.ws:spring-ws-core 4.1.0 수정 버전: 4.1.4 # pom.xml: bump <version>4.1.4</version> for org.springframework.ws:spring-ws-core 4.0.0 No fixed version published yet for org.springframework.ws:spring-ws-core (maven). Pin to a known-safe version or switch to an alternative.
3.1.0 No fixed version published yet for org.springframework.ws:spring-ws-core (maven). Pin to a known-safe version or switch to an alternative.