Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2022-41923 Discussion #844

Closed
mattmoss opened this issue Nov 21, 2022 · 5 comments
Closed

CVE-2022-41923 Discussion #844

mattmoss opened this issue Nov 21, 2022 · 5 comments
Assignees

Comments

@mattmoss
Copy link

mattmoss commented Nov 21, 2022

Issue description

This issue has been opened to facilitate discussion about CVE-2022-41923.

Technical details have not yet been released. We are providing a period of time for users to patch their applications before providing any technical details.

Patch

For information on patches, please see the Grails blog post.

Workaround

For a workaround, please see the Workaround repo.

More Information

If you have comments and/or questions, please add them here.

@mattmoss mattmoss self-assigned this Nov 21, 2022
@mattmoss mattmoss changed the title Discussion PLACEHOLDER CVE-2022-41923 Discussion Nov 22, 2022
@Pwdrkeg
Copy link

Pwdrkeg commented Dec 2, 2022

Is this considered a local or remote vulnerability? Understanding the scope can help determine how to mitigate.

@mattmoss
Copy link
Author

mattmoss commented Dec 2, 2022

The CVSS details are here: CVSS for CVE-2022-41923

Attack vector: network
Attack complexity: low
Privileges required: none
User interaction: none

If your application is vulnerable and is exposed to the remote network/Internet, then it can be attacked remotely.

@jaabax
Copy link

jaabax commented Jan 9, 2023

I updated the plugin from version 4.0.3 to 4.0.5 and now I'm getting the following error: ExceptionLog.txt

Any ideas? Been stuck with this issue for a while now.

Thank you.

@mattmoss
Copy link
Author

@jaabax
The base cause of that exception is that it cannot find org.springframework.web.util.UrlPathHelper.defaultInstance which is available in UrlPathHelper of the Spring Framework v5.2.9 and later.

Please check that your project has at least that version of the Spring Framework. You can determine what versions of each dependency are being used for each configuration by running a gradle dependency report.

@mattmoss
Copy link
Author

Additional details are available from Synacktiv who discovered this issue:
https://www.synacktiv.com/sites/default/files/2023-03/Synacktiv-Grails-Spring-Security-CVE-2022-41923.pdf

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants