CVE-2010-1622
Improper Control of Generation of Code ('Code Injection') in Spring Framework
EPSS 52.0%
描述
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing `class.classLoader.URLs[0]=jar:` followed by a URL of a crafted .jar file.
如何修補 CVE-2010-1622
要修補 CVE-2010-1622,請將受影響套件升級到下列已修補版本。
- Maven/org.springframework:spring—升級至 2.5.7 或更新版本
CVE-2010-1622 正在被利用嗎?
可能 — EPSS 為 52.0%,屬於高被利用機率區間,建議優先修補。
受影響套件(1)
- >= 2.5.0, < 2.5.7