Spring Beans 0day Vulnerability
Engström Per
per.engstrom at smhi.se
Wed Mar 30 12:45:11 UTC 2022
Hello again,
I’ll take your advice and make our installation non-editable by the account running the application. Thanks Scott.
I also did a search for ”@InitBinder” and ”dataBinder.setDisallowedFields” as suggested by the waning notice (https://www.javai.net/post/202203/spring-0day-vulnerability/) in the source code of project java-identity-provider (https://git.shibboleth.net/git/java-identity-provider.git). I did not get any matches, so I suppose we are in the clear for now.
Regards,
Per
Per Engström
Systemutvecklare / Systems Developer
SMHI / Swedish Meteorological and Hydrological Institute
SE - 601 76 NORRKÖPING
www.smhi.se<http://www.smhi.se>
E-post / Email: per.engstrom at smhi.se
Tel / Phone: +46 (0)11 495 83 37
Besöksadress / Street address: Folkborgsvägen 17
30 mars 2022 kl. 14:02 skrev Cantor, Scott via users <users at shibboleth.net<mailto:users at shibboleth.net>>:
On 3/30/22, 5:12 AM, "users on behalf of Engström Per" <users-bounces at shibboleth.net<mailto:users-bounces at shibboleth.net> on behalf of per.engstrom at smhi.se<mailto:per.engstrom at smhi.se>> wrote:
Does this need to be handled?
An actual security advisory issued by the Spring Project and a remediation, fix, or workaround would, yes. Until that happens, there's nothing we can do.
We can't hold 4.2 forever but we'll wait an appropriate amount of time to ship until we know what's going on. If warranted, we'll consider a patch for 4.1.
I will say that, as with some of the previous logging issues, the obvious thing everyone should do is fix any systems that are running their servlet container under accounts with write access to the IdP's code and configuration. Doing that is the quickest way to open oneself up to an RCE (ok, second quickest, but "don't run anything on the web" unfortunately isn't an option here).
-- Scott
--
For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw
To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net<mailto:users-unsubscribe at shibboleth.net>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20220330/b6c692d9/attachment.htm>
More information about the users
mailing list