GHSA-w3x5-427h-wfq6

    Dashboard / Vulnerabilities / GHSA-w3x5-427h-wfq6

    GHSA-w3x5-427h-wfq6

    Published: 9 Dec 2022Last Modified: 8 Nov 2023

    Summary: Spring Boot Admins integrated notifier support allows arbitrary code execution

    Details: ### Impact All users who run Spring Boot Admin Server, having enabled Notifiers (e.g. Teams-Notifier) and write access to environment variables via UI are possibly affected. ### Patches In the most recent releases of Spring Boot Admin 2.6.10 and 2.7.8 the issue is fixed by implementing `SimpleExecutionContext` of SpEL. This prevents the arbitrary code execution (i.e. SpEL injection). ### Workarounds * Disable any notifier * Disable write access (POST request) on `/env` actuator endpoint

    Affected packages

    Package

    Name: de.codecentric:spring-boot-admin

    Purl: pkg:maven/de.codecentric/spring-boot-admin

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -2.6.10

    Affected versions

    1.0.2
    1.0.3
    1.0.4
    1.0.5

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-w3x5-427h-wfq6 | CVE-DB