We are Using Crowd Server and current as per internal security scan it has detected Spring Framework Remote Code Execution (RCE) Vulnerability (Spring4Shell) vulnerability. As per the latest CVE Report (https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement#overview) it was mentioned that Spring Framework versions 5.3.0 to 5.3.17, 5.2.0 to 5.2.19, and older versions are impacted with the vulnerability.
We have upgraded Crowd Server to the latest version 4.4.1 and found that still Spring Framework version is 5.3.7 & 5.5.1.
Can you please let us if there are any patches which is or will be released to fix this vulnerability.
Hi @Avijit Chakraborty
At the current moment, Crowd use impacted versions of Spring but is not vulnerable to any known exploit. More details here: https://confluence.atlassian.com/kb/faq-for-cve-2022-22965-1115149136.html
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.