REDHAT-BUG-2463332: Medium severity VMware Spring Boot vulnerability
An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the attacker determining the secret and uploading changed classes, thereby achieving remote code execution in the remote application.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); DevTools remote secret comparison. Versions that are no longer supported are also affected per vendor advisory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2463332?
The severity of REDHAT-BUG-2463332 is high due to the potential for remote code execution.
How do I fix REDHAT-BUG-2463332?
To fix REDHAT-BUG-2463332, update to the latest supported version of VMware Spring Boot that addresses the vulnerability.
What versions of VMware Spring Boot are affected by REDHAT-BUG-2463332?
Versions 4.0.0 to 4.0.5, 3.5.0 to 3.5.13, 3.4.0 to 3.4.15, 3.3.0 to 3.3.18, and 2.7.0 to 2.7.32 of VMware Spring Boot are affected by REDHAT-BUG-2463332.
What type of attack is associated with REDHAT-BUG-2463332?
REDHAT-BUG-2463332 is associated with timing attacks that may allow an attacker to discover remote secrets.
What are the potential consequences of exploiting REDHAT-BUG-2463332?
Exploiting REDHAT-BUG-2463332 could lead to unauthorized remote code execution by uploading modified classes.