Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Spring Boot DevTools remote secret generated with a non-cryptographic PRNG
Vulnerability Description
When enabling Spring Boot DevTools support for a remote application target (for example a Docker container or Cloud Foundry app) from the Spring Tools Boot Dashboard, Spring Tools generates a shared secret that authenticates DevTools remote-restart uploads to the deployed application. This secret was generated using a non-cryptographic pseudo-random number generator rather than a cryptographically secure source of randomness. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier
CVSS Information
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
N/A
Vulnerability Title
Spring Tools for Eclipse 加密问题漏洞
Vulnerability Description
Spring Spring Tools for Eclipse是美国Spring公司开源的一套软件开发工具插件。 Spring Tools for Eclipse 5.2.0及之前版本存在加密问题漏洞,该漏洞源于使用非加密的伪随机数生成器生成共享密钥,导致远程重启上传的身份验证不充分。
CVSS Information
N/A
Vulnerability Type
N/A