Spring Beans 0day Vulnerability
Cantor, Scott
cantor.2 at osu.edu
Wed Mar 30 12:02:58 UTC 2022
On 3/30/22, 5:12 AM, "users on behalf of Engström Per" <users-bounces at shibboleth.net on behalf of per.engstrom at smhi.se> wrote:
> Does this need to be handled?
An actual security advisory issued by the Spring Project and a remediation, fix, or workaround would, yes. Until that happens, there's nothing we can do.
We can't hold 4.2 forever but we'll wait an appropriate amount of time to ship until we know what's going on. If warranted, we'll consider a patch for 4.1.
I will say that, as with some of the previous logging issues, the obvious thing everyone should do is fix any systems that are running their servlet container under accounts with write access to the IdP's code and configuration. Doing that is the quickest way to open oneself up to an RCE (ok, second quickest, but "don't run anything on the web" unfortunately isn't an option here).
-- Scott
More information about the users
mailing list