Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Spring4shell is missing SpringBoot update mention #504

Open
Eccenux opened this issue Apr 1, 2022 · 1 comment
Open

Spring4shell is missing SpringBoot update mention #504

Eccenux opened this issue Apr 1, 2022 · 1 comment

Comments

@Eccenux
Copy link

Eccenux commented Apr 1, 2022

  1. You didn't mention patches in top section: https://www.lunasec.io/docs/blog/spring-rce-vulnerabilities/#rce-in-spring-core
  2. Both core and Spring Boot was updated see: https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement
@freeqaz
Copy link
Member

freeqaz commented Apr 1, 2022

Thanks for catching this! I made a pass yesterday to add this information but apparently I missed these lines in the post. Fortunately, I've gotten more sleep now. With my head is on better today, I'll go get these changes in.

Thank you, @Eccenux !

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants