Skip to content

chore: update build configuration#3795

Open
AdhyaksaCyber wants to merge 1 commit into
spring-projects:mainfrom
AdhyaksaCyber:poc-dependabot
Open

chore: update build configuration#3795
AdhyaksaCyber wants to merge 1 commit into
spring-projects:mainfrom
AdhyaksaCyber:poc-dependabot

Conversation

@AdhyaksaCyber
Copy link
Copy Markdown

A Remote Code Execution (RCE) vulnerability exists in the Gradle build configuration (build.gradle) of spring-session. The build script executes shell commands derived from environment variables and system properties without sufficient sanitization, allowing an attacker to execute arbitrary code on the GitHub Actions runner during the build process.

@spring-projects-issues spring-projects-issues added the status: waiting-for-triage An issue we've not yet triaged label May 30, 2026
Signed-off-by: AdhyaksaCyber <bagusiqbal18@gmail.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

status: waiting-for-triage An issue we've not yet triaged

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants