CVE-2023-34053. spring-webmvc - Analysis of vulnerability

Description

Severity: High
Modules impacted:

mod-password-validator Volaris
mod-tags Volaris
mod-calendar Bama
mod-notes Spitfire
mod-entities-links Spitfire
mod-search Spitfire
mod-remote-storage Volaris 
edge-caiasoft Volaris -
mod-data-export-spring Firebird
mod-ebsconet Thunderjet
mod-data-export-worker Firebird
mod-bulk-operations Firebird
mod-fqm-manager Corsair
edge-fqm Corsair -
mod-lists Corsair
edge-courses TBD - fixed by https://github.com/folio-org/edge-courses/pull/7 because Spring Boot 3.1.6 uses Spring Framework 6.0.14

Link: https://spring.io/security/cve-2023-34053 - https://nvd.nist.gov/vuln/detail/CVE-2023-34053

Vulnerability: Spring Framework server Web Observations DoS Vulnerability

Package Name: spring-webmvc

Current spring-webmvc version is 6.0.12 // Fixed in 6.0.14

Checklist

hide

TestRail: Results

Activity

Show:

Julian LadischFebruary 1, 2024 at 7:42 PM

No FOLIO module configures Spring Framework server Web Observations: https://github.com/search?q=org%3Afolio-org+Observation&type=code

Therefore not vulnerable.

Craig McNallyJanuary 25, 2024 at 4:28 PM

Security Team notes... 

Need stories for edge-caisoft, edge-courses, edge-fqm to upgrade edge-api-utils, then release.

Still need to determine if we should target Poppy CSP or Quesnelia.

Julian LadischJanuary 25, 2024 at 1:02 AM

The mod-* modules are behind Okapi, an attacker cannot directly send a specially crafted HTTP requests to them.

Unresolved

Details

Assignee

Reporter

Priority

RCA Group

TBD

TestRail: Cases

Open TestRail: Cases

TestRail: Runs

Open TestRail: Runs

Created January 22, 2024 at 2:34 PM
Updated May 23, 2024 at 3:44 PM
TestRail: Cases
TestRail: Runs