1. Summary

Vulnerability Name Spring Boot Admin Remote Command Execution Vulnerability
Attack Type variable coverage
Time Discovered 2022-12-14
Updated Time 2022-12-15
CVE ID CVE-2022-46166

Spring boot admins is an open source administrative user interface for management of spring boot applications. All users who run Spring Boot Admin Server, having enabled Notifiers and write access to environment variables via UI are affected.

2. Affected Versions

Spring Boot Admin<2.6.10

2.7.0≤Spring Boot Admin<2.7.8

3.0.0:m1≤Spring Boot Admin<3.0.0:m6

3. Solution

Currently, the latest version has been officially released, and affected users are advised to update and upgrade to the latest version in time. The link is as follows: https://github.com/codecentric/spring-boot-admin/releases

4. Related Links

https://github.com/codecentric/spring-boot-admin/security/advisories/GHSA-w3x5-427h-wfq6

Listen To This Post

Search

Get in Touch

Get in Touch with Sangfor Team for Business Inquiry

Name
Email Address
Business Phone Number
Tell us about your project requirements

Related Articles

Roundup of Microsoft Patch Tuesday (June 2025)

Date : 13 Jun 2025
Read Now

CVE-2025-27817: Apache Kafka Connect Arbitrary File Read

Date : 12 Jun 2025
Read Now

CVE-2025-5419: Out-of-Bounds Read/Write Vulnerability in V8 in Google Chrome

Date : 03 Jun 2025
Read Now

See Other Product

Athena SASE - Secure Access Service Edge
Sangfor Athena NGFW - Next Generation Firewall
Sangfor Athena EPP - Modern Endpoint Protection Platform
Sangfor Athena NDR - Network Detection and Response
Cyber Command - NDR Platform
Endpoint Secure