GMS-2022-560: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) in org.springframework.boot:spring-boot-starter-web.
References
- github.com/advisories/GHSA-36p3-wjmg-h94x
- github.com/spring-projects/spring-boot/releases/tag/v2.5.12
- github.com/spring-projects/spring-boot/releases/tag/v2.6.6
- github.com/spring-projects/spring-framework/commit/002546b3e4b8d791ea6acccb81eb3168f51abb15
- github.com/spring-projects/spring-framework/releases/tag/v5.2.20.RELEASE
- github.com/spring-projects/spring-framework/releases/tag/v5.3.18
- nvd.nist.gov/vuln/detail/CVE-2022-22965
- spring.io/blog/2022/03/31/spring-framework-rce-early-announcement
- tanzu.vmware.com/security/cve-2022-22965
Detect and mitigate GMS-2022-560 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →