-
-
Notifications
You must be signed in to change notification settings - Fork 1.4k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Block more serialization gadgets (dbcp/tomcat, spring / CVE-2017-17485) #1855
Comments
I think this covers to-be-released CVE-2017-17485. |
Hello, |
The NIST page now lists "through 2.9.3" which is the latest version in Maven. |
Fix is in @bekwam One complication here is that we keep 2 or 3 open branches, typically, so ordering is not linear across patches from different minor version branches. Hence |
Apparently this is related to CVE-2017-17485, will resolve it. |
Does |
@yousifS I don't know. Probably not -- time to get out of 2.7 branch as it is not open any more. |
@yousifS Actually looking at this again... fix is indeed included in |
@cowtowncoder I thought so, but did not want to assume. http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17485, is still incorrect then. Thanks again for looking into it. |
@yousifS FWIW, there is also now |
More potential deserialization gadgets reported for:
For some of these need to check parent hierarchy.
Fixed in:
The text was updated successfully, but these errors were encountered: