← All tasks
javaobsidiandynamics/kafdrop #365Not a task: already works

CVE-2022-22965 in spring beans

envgap__obsidiandynamics__kafdrop-365

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
6ab52cf5f1f3d32ad84c1c433ed6fabe8c5edaa4
Manifest
pom.xml
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

obsidiandynamics/kafdrop #365 · read the original issue
Hi,



kafdrop container contains a vulnerable version of spring-beans (5.3.15).

https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement



A version upgrade to 5.3.18 is probably the best solution to fix this issue.



Can you have a look. Maybe it's not in use.
Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]