HomeSpacer
TV
Spacer
MOVIES
Spacer
MUSIC
Spacer
FASHION
Spacer
GEEKS
Spacer
BOOKS
Spacer
ART
Spacer
COMEDY
Spacer
DANCE
Spacer
CLASSICAL
Spacer
OPERA
Spacer
TRAVEL
Spacer
FITNESS
Spacer
THEATER
 
 LOG IN | REGISTER NOW!

GEEKS TODAY
TOP TOPICS
TOP MOBILE APPS
ABOUT US

Aspect Security Researchers Discover Remote Code Vulnerability in the Spring Framework


Related: Security

Aspect Security Researchers Discover Remote Code Vulnerability in the Spring Framework

Aspect Security, a pioneer in application security, today announced that its researchers have Discovered a significant security vulnerability in the Spring Framework. Exclusive data from Sonatype, the operator of the Central Repository, the industry's primary source for open-source components, shows that more than 1.3 million vulnerable instances of the Spring Framework has been downloaded by more than 22,000 organizations worldwide.

Spring is an open-source framework used by Java developers to build business-critical applications. The Expression Language (EL) vulnerability enables an attacker to use a remote code execution to invoke functionality and take over a machine or the organization's entire network. Once an attacker exploits this weakness, the enterprise loses control of the business systems built on the Spring Framework.

Dubbed Remote Code with Expression Language Injection by Arshan Dabirsiaghi, Director of Research, Aspect Security and Stefano DiPaola, CTO of Minded Security, this flaw was Discovered nearly 20 months ago and resulted in a fix by VMware in the latest version of the Spring Framework. Further research conducted by Aspect Security engineer Dan Amodio has uncovered additional issues that elevate the severity of the flaw, and Aspect cautions that additional steps need to be taken in order to protect organizations from Expression Language Injection vulnerabilities.

"It's difficult to quantify the depth and breadth of this problem since not every application is vulnerable, but any organization using Spring 3.0.5 or earlier is still at risk as these versions do not support disabling the double EL resolution," said Amodio. "The vulnerability leads to remote code execution, which can be devastating to an entire infrastructure. Many organizations are still using outdated components, which don't provide added protections by disabling this functionality. Even more alarming is that these flawed components are still being used to build applications which can present long-term security risks if gone unmanaged."

To keep applications free from third-party attacks and performance issues, Aspect Security recommends IT managers and developers using Spring update their libraries and opt-out of enabling double EL resolution. To avoid similar security instances in the future, organizations should consider Component Lifecycle Management (CLM) products that ensure the integrity of component-based software by analyzing usage, enforcing policy during development and delivering fixes for flawed components.

Leave Comments

Related Links
Scoop: NCIS: LOS ANGELES on CBS - Tuesday, June 4, 2013Scoop: NCIS: LOS ANGELES on CBS - Tuesday, June 4, 2013
by TV Scoop - May 20, 2013
Scoop: MODERN FAMILY on ABC - Wednesday, May 22, 2013Scoop: MODERN FAMILY on ABC - Wednesday, May 22, 2013
by TV Scoop - May 20, 2013
Microsoft Announces Winners and Finalists of the 2013 Partner of the Year AwardsMicrosoft Announces Winners and Finalists of the 2013 Partner of the Year Awards
May 20, 2013
AT&T Digital Life Launches In Seven Additional U.S. MarketsAT&T Digital Life Launches In Seven Additional U.S. Markets
May 20, 2013
BWW Blog: DROWSY CHAPERONE's Paige Faure - Traveling with BabyBWW Blog: DROWSY CHAPERONE's Paige Faure - Traveling with Baby
by Guest Blogger: Paige Faure - May 20, 2013

Past Articles by This Author:
  • BlackBerry to Launch BBM Messenger for iOS and Android this Summer
  • Apple vs. Samsung Update: Apple Adds Galaxy S4 to Massive Lawsuit
  • Condoleezza Rice, Walter Isaacson, Jim Collins to Headline ExactTarget Connections Sept. 17-19
  • ChannelAdvisor and Google Host Webinar to Share Tips for Success with Enhanced Campaigns
  • Leaf Unveils Second Generation of its Built-for-Business Tablet
  • BlackBerry Unveils Version 10.1 Now Available for Download for Enterprise Users
  • BlackBerry Announces Q5 a 'Youthful and Fun Smartphone'
  • BlackBerry to Webcast Keynote and Alicia Keys Performance from Orlando
  • McAfee and Intel Deliver New Model for Consumer Security - LiveSafe
  • Leaf Unveils New POS Android Tablet

    More Articles by This Author...

  • Get News & Specials!

    FLIPBOARD
    APPLE
    SAMSUNG
    GOOGLE
    TUMBLR
    VERIZON
    PANASONIC
    NETFLIX
    T-MOBILE
    BELKIN

    CBS HBO GAMING ACCESSORIES DISNEY SMASH CLOUD MOBILE IPHONE AMAZON

    Apple's Latest Milestone: App Store Hits 50 Billion Downloads APPLE Apple's Latest Milestone: App Store Hits 50 Billion Downloads
    Google Tells Microsoft to Remove Ad-Less YouTube App from Windows Phones GOOGLE Google Tells Microsoft to Remove Ad-Less YouTube App from Windows Phones
    Breaking News: Surprising No One, Yahoo! Has JUST Bought Tumblr for $1.1 BILLION Dollars TUMBLR Breaking News: Surprising No One, Yahoo! Has JUST Bought Tumblr for $1.1 BILLION Dollars
    Apple and Sony iRadio Negotiations Stymied by Song-Skipping APPLE Apple and Sony iRadio Negotiations Stymied by Song-Skipping
    Google TV to Receive Android Jelly Bean OS Upgrade LG ELECTRONICS Google TV to Receive Android Jelly Bean OS Upgrade
    RunKeeper Hits Pebble Smart Watch Today on iPhone and Android RunKeeper Hits Pebble Smart Watch Today on iPhone and Android
    ABC & Nielsen Partner to Measure Mobile Advertising Campaigns ABC ABC & Nielsen Partner to Measure Mobile Advertising Campaigns

    BWW TV World Logo
      
    BWW Movies World Logo
      
    BWW Fashion World Logo
      
    BWW Music World Logo
    BroadwayWorld.com Logo
      
    BWW Opera World Logo
      
    BWW Dance World Logo
      
    BWW Comedy World Logo
      

    All Materials Copyright 2013 Wisdom Digital Media | Privacy Policy | RSS/XMLFeeds