View Issue Details

IDProjectCategoryView StatusLast Update
0005263SymmetricDSBugpublic2022-04-11 19:28
Reporterelong Assigned Topmarzullo  
Prioritynormal 
Status closedResolutionfixed 
Product Version3.10.13 
Target Version3.13.4Fixed in Version3.13.4 
Summary0005263: CVE-2022-22965: Spring Version needs to use 5.2.20.RELEASE or 5.3.18 in order to not be vulnerable to this security issue
DescriptionCVE-2022-22965
These are the requirements for the specific scenario from the report:

JDK 9 or higher
Apache Tomcat as the Servlet container
Packaged as a traditional WAR (in contrast to a Spring Boot executable jar)
spring-webmvc or spring-webflux dependency
Spring Framework versions 5.3.0 to 5.3.17, 5.2.0 to 5.2.19, and older versions
Tagssecurity

Relationships

related to 0005248 closedpmarzullo CVE-2022-22965: Spring Version needs to use 5.2.20.RELEASE or 5.3.18 in order to not be vulnerable to this security issue 

Activities

There are no notes attached to this issue.

Issue History

Date Modified Username Field Change
2022-04-08 17:42 elong New Issue
2022-04-08 17:42 elong Status new => assigned
2022-04-08 17:42 elong Assigned To => pmarzullo
2022-04-08 17:42 elong Tag Attached: security
2022-04-08 17:42 elong Issue generated from: 0005248
2022-04-08 17:42 elong Relationship added related to 0005248
2022-04-08 17:42 elong Status assigned => resolved
2022-04-08 17:42 elong Resolution open => fixed
2022-04-08 17:42 elong Fixed in Version => 3.13.4
2022-04-08 17:42 elong Target Version 3.13.5 => 3.13.4
2022-04-11 19:28 admin Status resolved => closed