Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2023-44794 on spring_framework #6612

Open
vincenzo-scia opened this issue Apr 19, 2024 · 4 comments
Open

CVE-2023-44794 on spring_framework #6612

vincenzo-scia opened this issue Apr 19, 2024 · 4 comments
Labels

Comments

@vincenzo-scia
Copy link

According to NIST NVD, spring_framework 6.0.17 (or more in general spring_framework > 5.3.0) is affected by CVE-2023-44794 (source: https://nvd.nist.gov/vuln/detail/CVE-2023-44794). However, DependencyCheck Maven (version 7.4.4) is not reporting this CVE for spring_framework 6.0.17.

Question: do you marked this as a false positive on the basis of what stated in this issue spring-projects/spring-framework#31862?

@OrangeDog
Copy link

https://github.com/jeremylong/DependencyCheck/blob/main/core/src/main/resources/dependencycheck-base-suppression.xml is the bundled suppressions file. I see nothing that would suppress this if it were being incorrectly detected.

@aikebah
Copy link
Collaborator

aikebah commented Apr 27, 2024

DependencyCheck Maven (version 7.4.4)

is massively outdated and unsupported. Upgrade to latest 9.x and check again.

@aikebah
Copy link
Collaborator

aikebah commented Apr 27, 2024

Also note that NIST does not mark Spring framework as affected, but Sa-Token when running on Spring

@vincenzo-scia
Copy link
Author

vincenzo-scia commented Apr 29, 2024

Also note that NIST does not mark Spring framework as affected, but Sa-Token when running on Spring

Correct, thank you. What led me astray was the detail page of cpe:2.3:a:vmware:spring_framework:6.0.17 which (in my eyes) seemed to ascribe CVE-2023-44794 directly to Spring Framework:

https://nvd.nist.gov/vuln/search/results?form_type=Advanced&results_type=overview&isCpeNameSearch=true&seach_type=all&query=cpe:2.3:a:vmware:spring_framework:6.0.17

The detail page of CVE-2023-44794 explains more precisely what you stated above.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants