CVE-2022-22965 in spring beans
envgap__obsidiandynamics__kafdrop-365
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
6ab52cf5f1f3d32ad84c1c433ed6fabe8c5edaa4- Manifest
pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
obsidiandynamics/kafdrop #365 · read the original issue
Hi, kafdrop container contains a vulnerable version of spring-beans (5.3.15). https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement A version upgrade to 5.3.18 is probably the best solution to fix this issue. Can you have a look. Maybe it's not in use.
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]