Questo sito potrebbe offrire funzionalità limitate durante le operazioni di manutenzione per migliorare l'esperienza utente. Se un articolo non risolve il tuo problema e vuoi richiedere supporto, la nostra comunità di supporto è pronta ad aiutarti tramite @FirefoxSupport su Twitter e /r/firefox su Reddit.

Cerca nel supporto

Attenzione alle mail truffa. Mozilla non chiederà mai di chiamare o mandare messaggi a un numero di telefono o di inviare dati personali. Segnalare qualsiasi attività sospetta utilizzando l'opzione “Segnala abuso”.

Ulteriori informazioni

Questa discussione è archiviata. Inserire una nuova richiesta se occorre aiuto.

Java Spring Framework

  • 1 risposta
  • 1 ha questo problema
  • 1 visualizzazione
  • Ultima risposta di James

more options

On March 31, 2022 a pair of significant vulnerabilities were identified in the Java Spring Framework which would allow an attacker to execute malicious code. • CVE-2022-22963 - https://tanzu.vmware.com/security/cve-2022-22963 • CVE-2022-22965 - https://tanzu.vmware.com/security/cve-2022-22965

It is critical for all of our vendors to determine if their software is impacted so that remediation steps can be taken. We need your company to respond to the following questions immediately:

• Is your product impacted by CVE-2022-22963 or CVE-2022-22965? • Is your product built on Java? • Does your product depend on the Spring Cloud Function project? If so, what version? • Does your product depend on Spring Framework? If so, what version? • Does the product require JDK 9 or higher? • Does the product have a dependency on spring-webmvc? • Does the product have a dependency on spring-webflux?

Thanks

On March 31, 2022 a pair of significant vulnerabilities were identified in the Java Spring Framework which would allow an attacker to execute malicious code. • CVE-2022-22963 - https://tanzu.vmware.com/security/cve-2022-22963 • CVE-2022-22965 - https://tanzu.vmware.com/security/cve-2022-22965 It is critical for all of our vendors to determine if their software is impacted so that remediation steps can be taken. We need your company to respond to the following questions immediately: • Is your product impacted by CVE-2022-22963 or CVE-2022-22965? • Is your product built on Java? • Does your product depend on the Spring Cloud Function project? If so, what version? • Does your product depend on Spring Framework? If so, what version? • Does the product require JDK 9 or higher? • Does the product have a dependency on spring-webmvc? • Does the product have a dependency on spring-webflux? Thanks

Tutte le risposte (1)

more options

jeffrey.branham said

On March 31, 2022 a pair of significant vulnerabilities were identified in the Java Spring Framework which would allow an attacker to execute malicious code. • CVE-2022-22963 - https://tanzu.vmware.com/security/cve-2022-22963 • CVE-2022-22965 - https://tanzu.vmware.com/security/cve-2022-22965 • Is your product impacted by CVE-2022-22963 or CVE-2022-22965? • Is your product built on Java? • Does the product require JDK 9 or higher?

The desktop Firefox web browser for Windows, macOS and Linux (and also the mobile versions for iOS and Android) has never required the Java Plugin from Oracle to work. Firefox has not allowed the Java Plugin (NPAPI) to run for a long while now.

Why do Java, Silverlight, Adobe Acrobat and other plugins no longer work? https://support.mozilla.org/en-US/kb/npapi-plugins

Also if any web browser was vulnerable it would have been mentioned in CVE-2022-22963 or CVE-2022-22965

Also if Firefox was vulnerable to this it would be listed in https://www.mozilla.org/security/known-vulnerabilities/firefox/ https://www.mozilla.org/security/known-vulnerabilities/