CVE-2022-27772 (High) detected in spring-boot-1.5.22.RELEASE.jar
mend-bolt-for-github opened this issue · comments
CVE-2022-27772 - High Severity Vulnerability
Vulnerable Library - spring-boot-1.5.22.RELEASE.jar
Spring Boot
Library home page: https://projects.spring.io/spring-boot/
Path to dependency file: /pom.xml
Path to vulnerable library: /home/wss-scanner/.m2/repository/org/springframework/boot/spring-boot/1.5.22.RELEASE/spring-boot-1.5.22.RELEASE.jar
Dependency Hierarchy:
- spring-boot-starter-security-1.5.22.RELEASE.jar (Root Library)
- spring-boot-starter-1.5.22.RELEASE.jar
- ❌ spring-boot-1.5.22.RELEASE.jar (Vulnerable Library)
- spring-boot-starter-1.5.22.RELEASE.jar
Found in base branch: master
Vulnerability Details
** UNSUPPORTED WHEN ASSIGNED ** spring-boot versions prior to version v2.2.11.RELEASE was vulnerable to temporary directory hijacking. This vulnerability impacted the org.springframework.boot.web.server.AbstractConfigurableWebServerFactory.createTempDir method. NOTE: This vulnerability only affects products and/or versions that are no longer supported by the maintainer.
Publish Date: 2022-03-30
URL: CVE-2022-27772
CVSS 3 Score Details (7.8)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
Suggested Fix
Type: Upgrade version
Origin: GHSA-cm59-pr5q-cw85
Release Date: 2022-03-30
Fix Resolution (org.springframework.boot:spring-boot): 2.2.11.RELEASE
Direct dependency fix Resolution (org.springframework.boot:spring-boot-starter-security): 2.2.11.RELEASE
Step up your Open Source Security Game with Mend here
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.