We are Using Crowd Server and current as per internal security scan it has detected Spring Framework Remote Code Execution (RCE) Vulnerability (Spring4Shell) vulnerability. As per the latest CVE Report (https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement#overview) it was mentioned that Spring Framework versions 5.3.0 to 5.3.17, 5.2.0 to 5.2.19, and older versions are impacted with the vulnerability.
We have upgraded Crowd Server to the latest version 4.4.1 and found that still Spring Framework version is 5.3.7 & 5.5.1.
Can you please let us if there are any patches which is or will be released to fix this vulnerability.
Hi @Avijit Chakraborty
At the current moment, Crowd use impacted versions of Spring but is not vulnerable to any known exploit. More details here: https://confluence.atlassian.com/kb/faq-for-cve-2022-22965-1115149136.html
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.