Spring Boot Admins integrated notifier support allows arbitrary code execution
Published Dec 9, 2022
9.8
CRITICALCVSS 3.1
EPSS 1.48%
Description
Spring boot admins is an open source administrative user interface for management of spring boot applications. All users who run Spring Boot Admin Server, having enabled Notifiers (e.g. Teams-Notifier) and write access to environment variables via UI are affected. Users are advised to upgrade to the most recent releases of Spring Boot Admin 2.6.10 and 2.7.8 to resolve this issue. Users unable to upgrade may disable any notifier or disable write access (POST request) on `/env` actuator endpoint.
Affected products
-
- Version < 2.6.10StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Codecentric | Spring-Boot-Admin | n/a |
|
- < 2.6.10
- ≥ 2.7.0 · < 2.7.8
- 3.0.0
- 3.0.0
- 3.0.0
- 3.0.0
- 3.0.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://github.com/advisories/GHSA-w3x5-427h-wfq6 Advisory
- https://github.com/codecentric/spring-boot-admin/commit/c14c3ec12533f71f84de9ce3ce5ceb7991975f75 x_refsource_MISCPatchThird Party Advisory
- https://github.com/codecentric/spring-boot-admin/security/advisories/GHSA-w3x5-427h-wfq6 x_refsource_CONFIRMMitigationThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-w3x5-427h-wfq6 | Advisory | |
| https://github.com/codecentric/spring-boot-admin/commit/c14c3ec12533f71f84de9ce3ce5ceb7991975f75 | x_refsource_MISCPatchThird Party Advisory | |
| https://github.com/codecentric/spring-boot-admin/security/advisories/GHSA-w3x5-427h-wfq6 | x_refsource_CONFIRMMitigationThird Party Advisory |
Change history (0)
No recorded changes yet.