Spring Beans 0day Vulnerability

Cantor, Scott cantor.2 at osu.edu
Wed Mar 30 12:02:58 UTC 2022


On 3/30/22, 5:12 AM, "users on behalf of Engström Per" <users-bounces at shibboleth.net on behalf of per.engstrom at smhi.se> wrote:

>  Does this need to be handled?

An actual security advisory issued by the Spring Project and a remediation, fix, or workaround would, yes. Until that happens, there's nothing we can do.

We can't hold 4.2 forever but we'll wait an appropriate amount of time to ship until we know what's going on. If warranted, we'll consider a patch for 4.1.

I will say that, as with some of the previous logging issues, the obvious thing everyone should do is fix any systems that are running their servlet container under accounts with write access to the IdP's code and configuration. Doing that is the quickest way to open oneself up to an RCE (ok, second quickest, but "don't run anything on the web" unfortunately isn't an option here).

-- Scott




More information about the users mailing list