Support Center > 详细页 > 安全公告详细

Security Notice - Statement On Spring Framework RCE Vulnerability

  • Initial Release Date 2022-04-01 09:31:40
  • last Release Date 2022-04-01 09:31:40
Vulnerability Summary

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

Product Impact
Products Impacted(Y/N/Under Investigation)
Servers V1 N
Servers V2 N
AIStation

Resource
Revision History

2022-04-01 V1.0 INITIAL

Declaration

KAYTUS shall not be liable for technical or editorial errors or omissions contained herein. The information provided is provided "as is" without warranty of any kind. To the extent permitted by law, KAYTUS disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose, title and non-infringement. In no event shall KAYTUS or any of its directly or indirectly controlled subsidiaries or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. Your use of the document, by whatsoever means, will be totally at your own risk. KAYTUS is entitled to amend or update this document from time to time.