yanglin created AXIS2-6032:
------------------------------

             Summary: About Spring RCE 0Days Vulnerability
                 Key: AXIS2-6032
                 URL: https://issues.apache.org/jira/browse/AXIS2-6032
             Project: Axis2
          Issue Type: Bug
    Affects Versions: 1.8.0, 1.7.9
            Reporter: yanglin


Hello !

Is AXIS2 affected by spring rce vulnerability?

if so , will a new version be released ?

 

CVE-2022-22965: A Spring MVC or Spring WebFlux application running on JDK 9+ 
may be vulnerable to remote code execution (RCE) via data binding

https://nvd.nist.gov/vuln/detail/CVE-2022-22965



--
This message was sent by Atlassian Jira
(v8.20.1#820001)

---------------------------------------------------------------------
To unsubscribe, e-mail: java-dev-unsubscr...@axis.apache.org
For additional commands, e-mail: java-dev-h...@axis.apache.org

Reply via email to