CVE-2015-0201
Moderate severity vulnerability that affects org.springframework:spring-core
EPSS 1.9%
描述
The Java SockJS client in Pivotal Spring Framework 4.1.x before 4.1.5 generates predictable session ids, which allows remote attackers to send messages to other sessions via unspecified vectors.
如何修補 CVE-2015-0201
要修補 CVE-2015-0201,請將受影響套件升級到下列已修補版本。
- Maven/org.springframework:spring-core—升級至 4.1.5 或更新版本
CVE-2015-0201 正在被利用嗎?
低 — EPSS 為 1.9%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- >= 4.1.0, < 4.1.5