Bug 23975 - springframework new security issues CVE-2018-1257, CVE-2018-1270, CVE-2018-11039, CVE-2018-11040, CVE-2018-15756, CVE-2020-5421
Summary: springframework new security issues CVE-2018-1257, CVE-2018-1270, CVE-2018-11...
Status: RESOLVED OLD
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 7
Hardware: All Linux
Priority: Normal critical
Target Milestone: ---
Assignee: Java Stack Maintainers
QA Contact: Sec team
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2018-12-08 19:00 CET by David Walser
Modified: 2021-07-01 18:18 CEST (History)
2 users (show)

See Also:
Source RPM: springframework-3.2.18-2.mga7.src.rpm
CVE: CVE-2020-5421
Status comment:


Attachments

Description David Walser 2018-12-08 19:00:14 CET
Spring Framework is vulnerable to a security issue:
https://nvd.nist.gov/vuln/detail/CVE-2018-1257

It's fixed in newer branches, but we still have an older unsupported branch, so a fix would need to be backported.

There's another issue that I believe doesn't affect us:
https://nvd.nist.gov/vuln/detail/CVE-2018-1258

Mageia 6 is also affected.
David Walser 2018-12-08 19:00:21 CET

Whiteboard: (none) => MGA6TOO

David Walser 2019-06-23 19:31:59 CEST

Whiteboard: MGA6TOO => MGA7TOO, MGA6TOO

Nicolas Lécureuil 2020-05-22 14:08:03 CEST

CC: (none) => mageia
Whiteboard: MGA7TOO, MGA6TOO => MGA7TOO

Zombie Ryushu 2020-12-23 23:13:37 CET

CVE: (none) => CVE-2020-5421
URL: (none) => https://nvd.nist.gov/vuln/detail/CVE-2020-5421
CC: (none) => zombie_ryushu

Comment 1 David Walser 2020-12-24 00:33:39 CET
Another issue fixed in newer branches, but would need to be backported:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-5421
https://nvd.nist.gov/vuln/detail/CVE-2020-5421

Package was (mercifully) dropped from Cauldron.

Whiteboard: MGA7TOO => (none)
Summary: springframework new security issue CVE-2018-1257 => springframework new security issues CVE-2018-1257 and CVE-2020-5421
Version: Cauldron => 7
URL: https://nvd.nist.gov/vuln/detail/CVE-2020-5421 => (none)

Comment 2 David Walser 2021-05-28 22:57:11 CEST
Debian-LTS has issued an advisory on April 23:
https://www.debian.org/lts/security/2021/dla-2635

The issues are fixed upstream in 4.3.20.

Severity: normal => critical
Summary: springframework new security issues CVE-2018-1257 and CVE-2020-5421 => springframework new security issues CVE-2018-1257, CVE-2018-1270, CVE-2018-11039, CVE-2018-11040, CVE-2018-15756, CVE-2020-5421

Comment 3 David Walser 2021-07-01 18:18:40 CEST
https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/

Resolution: (none) => OLD
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.