Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Code injection issue for java-spring-cloud-stream-template
Vulnerability Description
@asyncapi/java-spring-cloud-stream-template generates a Spring Cloud Stream (SCSt) microservice. In versions prior to 0.7.0 arbitrary code injection was possible when an attacker controls the AsyncAPI document. An example is provided in GHSA-xj6r-2jpm-qvxp. There are no mitigations available and all users are advised to update.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Vulnerability Title
Java Spring Cloud Stream template 代码注入漏洞
Vulnerability Description
Java Spring Cloud Stream template是AsyncAPI 生成器的一个模板。 Java Spring Cloud Stream 模板 0.7.0之前的版本生成SpringCloudStream(SCSt)微服务存在代码注入漏洞,攻击者可利用该漏洞控制AsyncAPI文档,注入任意代码。建议所有用户进行更新。
CVSS Information
N/A
Vulnerability Type
N/A