5 ms·
The blog post on Kendra looks like a draft hoping for an actual confirmation/poc to come up, the mitigation just explains manually how to replicate the PR #2807
by Copenjin 5y ago
The blog post on Kendra looks like a draft hoping for an actual confirmation/poc to come up, the mitigation just explains manually how to replicate the PR #28075.
Edit: They just translated the chinese post you can find linked here.
[1] https://github.com/spring-projects/spring-framework/pull/28075 https://github.com/spring-projects/spring-framework/pull/280...
- nikeee 5y agoA comment [0] on the commit of that PR points to this site [1]. This site mentions that the vulnerability is similar to CVE-2010-1622 [2, 3]. Maybe this could help finding the issue, toegether with the recommended actions and mentioned classes (CachedIntrospectionResults, CacheResultInterceptor). [0]: https://github.com/spring-projects/spring-framework/commit/7f7fb58dd0dae86d22268a4b59ac7c72a6c22529#r69860640 https://github.com/spring-projects/spring-framework/commit/7... [1]: https://mp.weixin.qq.com/s/P-NEJzUUjIyemkSe_RbicQ https://mp.weixin.qq.com/s/P-NEJzUUjIyemkSe_RbicQ [2]: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1622 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1622 [3]: https://www.exploit-db.com/exploits/13918 https://www.exploit-db.com/exploits/13918