RSS   Vulnerabilities for
'Java-spring-cloud-stream-template'
   RSS

2021-08-11
 
CVE-2021-37694

CWE-94
 

 
@asyncapi/java-spring-cloud-stream-template generates a Spring Cloud Stream (SCSt) microservice. In versions prior to 0.7.0 arbitrary code injection was possible when an attacker controls the AsyncAPI document. An example is provided in GHSA-xj6r-2jpm-qvxp. There are no mitigations available and all users are advised to update.

 


Copyright 2024, cxsecurity.com

 

Back to Top