Spring Boot 2 も 3 も Spring Security 使ってるところは影響しそうかな。 "CVE-2023-34034: WebFlux Security Bypass With Un-Prefixed Double Wildcard Pattern" "CVE-2023-34035: Authorization rules can be misconfigured when using multiple servlets" Spring Security 5.6.12, 5.7.10, 5.8.5, 6.0.5, and 6.1.2 are available now, including fixes for CVE-2023-34034 and CVE-2023-34035 https://spring.io/blog/2023/07/24/spring-security-5-6-12-5-7-10-5-8-5-6-0-5-and-6-1-2-are-available-now
[Mastodon] 2023-07-25 07:52:09
|