Skip to content
This repository was archived by the owner on Jan 3, 2023. It is now read-only.
This repository was archived by the owner on Jan 3, 2023. It is now read-only.

同学,您这个项目引入了110个开源组件,存在1个漏洞,辛苦升级一下 #68

Description

检测到 RobbiNespu/ESS 一共引入了110个开源组件,存在1个漏洞

漏洞标题:Thymeleaf-Spring5 安全漏洞
缺陷组件:org.thymeleaf:thymeleaf-spring5@3.0.12.RELEASE
漏洞编号:CVE-2021-43466
漏洞描述:Thymeleaf-Spring5是Thymeleaf团队的一个适用于 Web 和独立环境的开源现代服务器端 Java 模板引擎。
Thymeleaf-Spring5 存在安全漏洞,该漏洞源于外部输入数据构造可执行命令过程中,网络系统或产品未正确过滤其中的特殊元素。攻击者可利用该漏洞执行非法命令。
影响范围:(∞, 3.0.13.RELEASE)
最小修复版本:3.0.13.RELEASE
缺陷组件引入路径:io.robbinespu:ESS@0.0.2-SNAPSHOT->org.springframework.boot:spring-boot-starter-thymeleaf@2.6.1->org.thymeleaf:thymeleaf-spring5@3.0.12.RELEASE

另外还有几个漏洞,详细报告:https://mofeisec.com/jr?p=i20469

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions