Sandor Molnar created KNOX-3428:
-----------------------------------
Summary: Upgrade Spring to 6.2.19 due to CVEs
Key: KNOX-3428
URL: https://issues.apache.org/jira/browse/KNOX-3428
Project: Apache Knox
Issue Type: Bug
Components: Server
Affects Versions: 3.0.0
Reporter: Sandor Molnar
Assignee: Sandor Molnar
Fix For: 3.1.0
Applications may be vulnerable to a Regular Expression Denial of Service
(ReDoS) attack if an attacker is able to provide a pattern which is then
directly or indirectly supplied to one of the following methods in
AntPathMatcher: match(String pattern, String path), matchStart(String pattern,
String path), extractUriTemplateVariables(String pattern, String path).
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through
6.1.27; 5.3.0 through 5.3.48.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)