REDHAT-BUG-606706: High severity SpringSource Spring Framework vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2010-1622 to the following vulnerability:
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote attackers to execute arbitrary code via an HTTP request containing class.classLoader.URLs[0]=jar: followed by a URL of a crafted .jar file.
References: [1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1622 [2] http://www.securityfocus.com/archive/1/511877 [3] http://www.exploit-db.com/exploits/13918 [4] http://www.springsource.com/security/cve-2010-1622 [5] http://www.securityfocus.com/bid/40954
Credit: The issue was discovered by Meder Kydyraliev, Google Security Team
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-606706?
The severity of REDHAT-BUG-606706 is critical as it allows remote attackers to exploit the vulnerability in the Spring Framework.
How do I fix REDHAT-BUG-606706?
To fix REDHAT-BUG-606706, upgrade to Spring Framework version 2.5.6.SEC02, 2.5.7.SR01, or 3.0.3 or later.
What versions of Spring Framework are affected by REDHAT-BUG-606706?
The affected versions of Spring Framework are those prior to 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3.
What type of attacks can REDHAT-BUG-606706 be used for?
REDHAT-BUG-606706 can be exploited for remote code execution attacks against applications using the affected versions of Spring Framework.
Is there a workaround for REDHAT-BUG-606706?
There are no known workarounds for REDHAT-BUG-606706; the recommended action is to upgrade to a fixed version.