← Back

CVE-2022-46166

nvd nist
Published: Dec 9, 2022Modified: Nov 21, 2024

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Spring boot admins is an open source administrative user interface for management of spring boot applications. All users who run Spring Boot Admin Server, having enabled Notifiers (e.g. Teams-Notifier) and write access to environment variables via UI are affected. Users are advised to upgrade to the most recent releases of Spring Boot Admin 2.6.10 and 2.7.8 to resolve this issue. Users unable to upgrade may disable any notifier or disable write access (POST request) on `/env` actuator endpoint.

Affected (7)

1 product
Spring Boot Admin
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Codecentric
Before 2.6.10
From 2.7.0 to 2.7.8
Version 3.0.0 m1
Version 3.0.0 m2
Version 3.0.0 m3
Version 3.0.0 m4
Version 3.0.0 m5

References (4)

Source: security-advisories@github.com
MitigationThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party Advisory

Timeline

No history available yet.