Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

Spring Framework Remote Code Execution (RCE) Vulnerability (Spring4Shell)

Avijit Chakraborty
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
May 11, 2022

We are Using Crowd Server and current as per internal security scan it has detected Spring Framework Remote Code Execution (RCE) Vulnerability (Spring4Shell) vulnerability. As per the latest CVE Report (https://spring.io/blog/2022/03/31/spring-framework-rce-early-announcement#overview) it was mentioned that Spring Framework versions 5.3.0 to 5.3.17, 5.2.0 to 5.2.19, and older versions are impacted with the vulnerability. 

We have upgraded Crowd Server to the latest version 4.4.1 and found that still Spring Framework version is 5.3.7 & 5.5.1. 

Can you please let us if there are any patches which is or will be released to fix this vulnerability. 

1 answer

1 vote
Ruslan Tkachuk May 20, 2022

Hi @Avijit Chakraborty 

At the current moment, Crowd use impacted versions of Spring but is not vulnerable to any known exploit. More details here: https://confluence.atlassian.com/kb/faq-for-cve-2022-22965-1115149136.html

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
SERVER
TAGS
AUG Leaders

Atlassian Community Events