Sandor Molnar created KNOX-3428:
-----------------------------------

             Summary: Upgrade Spring to 6.2.19 due to CVEs
                 Key: KNOX-3428
                 URL: https://issues.apache.org/jira/browse/KNOX-3428
             Project: Apache Knox
          Issue Type: Bug
          Components: Server
    Affects Versions: 3.0.0
            Reporter: Sandor Molnar
            Assignee: Sandor Molnar
             Fix For: 3.1.0


Applications may be vulnerable to a Regular Expression Denial of Service 
(ReDoS) attack if an attacker is able to provide a pattern which is then 
directly or indirectly supplied to one of the following methods in 
AntPathMatcher: match(String pattern, String path), matchStart(String pattern, 
String path), extractUriTemplateVariables(String pattern, String path).

Affected versions:

Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 
6.1.27; 5.3.0 through 5.3.48.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to