Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Spring Cloud AWS: Missing SNS message signature verification allows spoofing of HTTP/HTTPS endpoint notifications
Vulnerability Description
Spring Cloud AWS simplifies using AWS managed services in a Spring and Spring Boot applications. From 3.0.0 to 4.0.1, pplications using Spring Cloud AWS SNS HTTP/HTTPS endpoint support (@NotificationMessageMapping, @NotificationSubscriptionMapping, @NotificationUnsubscribeConfirmationMapping) did not verify the signature of incoming SNS messages. An unauthenticated attacker who knows the endpoint URL could send crafted HTTP POST requests mimicking SNS Notification or SubscriptionConfirmation messages. This vulnerability is fixed in 4.0.2.
CVSS Information
N/A
Vulnerability Type
对数据真实性的验证不充分
Vulnerability Title
Spring Cloud AWS 数据伪造问题漏洞
Vulnerability Description
Spring Cloud AWS是awspring开源的一个面向AWS云服务集成的Spring生态开发框架。 Spring Cloud AWS 3.0.0至4.0.1版本存在数据伪造问题漏洞,该漏洞源于使用SNS HTTP/HTTPS端点支持时未验证传入SNS消息的签名,未经身份验证的攻击者知道端点URL后可发送特制HTTP POST请求模拟SNS通知或订阅确认消息。
CVSS Information
N/A
Vulnerability Type
N/A